CVE-2026-7002: KLiK SocialMediaWebsite Private Message get_message_ajax.php sql injection
A vulnerability was determined in KLiK SocialMediaWebsite up to 1.0.1. This vulnerability affects unknown code of the file /includes/get_message_ajax.php of the component Private Message Handler. Executing a manipulation of the argument c_id can lead to sql injection. It is possible to launch the attack remotely.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-7002?
CVE-2026-7002 is classified as a high-severity SQL injection vulnerability that can potentially allow unauthorized access to sensitive data.
How do I fix CVE-2026-7002?
To fix CVE-2026-7002, it is recommended to upgrade KLiK SocialMediaWebsite to version 1.0.2 or higher, as this version includes security patches addressing the vulnerability.
What are the symptoms of exploitation for CVE-2026-7002?
Exploitation of CVE-2026-7002 may lead to unexpected database behavior or unauthorized data retrieval through the vulnerable 'get_message_ajax.php' file.
Who is affected by CVE-2026-7002?
CVE-2026-7002 affects all users running KLiK SocialMediaWebsite versions up to and including 1.0.1.
What component of KLiK SocialMediaWebsite is vulnerable in CVE-2026-7002?
The vulnerable component in CVE-2026-7002 is the Private Message Handler located in the 'includes/get_message_ajax.php' file.