PT-2022-26252 · Unknown · Klik Socialmediawebsite

Published

2022-11-29

·

Updated

2025-04-25

·

CVE-2022-42100

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions KLiK SocialMediaWebsite version 1.0.1
Description The issue allows attackers to store XSS via location input in the reply-form, potentially affecting user security.
Recommendations For KLiK SocialMediaWebsite version 1.0.1, consider disabling the location input feature in the reply-form until a patch is available to prevent the storage of XSS attacks. Restrict access to the reply-form to minimize the risk of exploitation. Avoid using the location input field in the reply-form until the issue is resolved.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2022-42100

Affected Products

Klik Socialmediawebsite