← Back to list

KLiK SocialMediaWebsite Version 1.0.1 — Stored XSS Vulnerability at Forum Subject

Vulnerability Explanation:

GrimTheRipper · 2022-09-28 04:05 · 0 claps · 1.6 min read
#cross-site-scripting #code-execution #web-vulnerabilities #klik #xss-attack
Open on Medium ↗
Wiki topics: 🔒 · Cybersecurity

[CVE-2022–42099]KLiK SocialMediaWebsite Version 1.0.1 — Stored XSS Vulnerability at Forum Subject

Vulnerability Explanation:

KLiK SocialMediaWebsite Version 1.0.1 has XSS vulnerabilities that allow attackers to store XSS via location Forum Subject input.

Affected Component:

http://[ip]/KLiK/create-topic.php

Payload :

<img src=”test” onerror=confirm(“Grim-The-Ripper-Team-by-SOSECURE-Thailand”)>

Tested on:

  1. KLiK SocialMediaWebsite Version 1.0.1 https://github.com/msaad1999/KLiK-SocialMediaWebsite
  2. Google Chrome Version 103.0.5060.114 (Official Build) (64-bit)

Steps to attack:

  1. Login with user credentials.

  1. Go to the “Forum”(any forum) as show in the picture

  1. Next, click on the “Forum Subject” input then enter the XSS payload and press the Create Forum button then there will be a message saying that the forum has been successfully created as in the picture.

  1. Next, go back to the index.php page and you will see that a new forum has been created.

  1. After, go to that forum The XSS payload will run immediately.

Discoverer:

Grim The Ripper Team by SOSECURE Thailand

Reference:

https://github.com/msaad1999/KLiK-SocialMediaWebsite


메타데이터
post_id
a453789736f2
slug
klik-socialmediawebsite-version-1-0-1-stored-xss-vulnerability-at-forum-subject-a453789736f2
url
https://medium.com/@grimthereaperteam/klik-socialmediawebsite-version-1-0-1-stored-xss-vulnerability-at-forum-subject-a453789736f2
canonical_url
https://medium.com/@grimthereaperteam/klik-socialmediawebsite-version-1-0-1-stored-xss-vulnerability-at-forum-subject-a453789736f2
author_url
https://medium.com/@grimthereaperteam
status
ok
fetched_at
2026-06-29 22:44:20