PT-2026-35177 · Klik · Socialmediawebsite

G111

·

Published

2026-04-25

·

Updated

2026-04-25

·

CVE-2026-7002

CVSS v2.0

7.5

High

AV:N/AC:L/Au:N/C:P/I:P/A:P
A vulnerability was determined in KLiK SocialMediaWebsite up to 1.0.1. This vulnerability affects unknown code of the file /includes/get message ajax.php of the component Private Message Handler. Executing a manipulation of the argument c id can lead to sql injection. It is possible to launch the attack remotely.

Fix

SQL injection

Special Elements Injection

Weakness Enumeration

Related Identifiers

CVE-2026-7002

Affected Products

Socialmediawebsite