KLiK SocialMediaWebsite Version 1.0.1 — Stored XSS Vulnerability at Forum Subject
Vulnerability Explanation:
Wiki topics:
🔒 · Cybersecurity
[CVE-2022–42099]KLiK SocialMediaWebsite Version 1.0.1 — Stored XSS Vulnerability at Forum Subject
Vulnerability Explanation:
KLiK SocialMediaWebsite Version 1.0.1 has XSS vulnerabilities that allow attackers to store XSS via location Forum Subject input.
Affected Component:
http://[ip]/KLiK/create-topic.php
Payload :
<img src=”test” onerror=confirm(“Grim-The-Ripper-Team-by-SOSECURE-Thailand”)>
Tested on:
- KLiK SocialMediaWebsite Version 1.0.1 https://github.com/msaad1999/KLiK-SocialMediaWebsite
- Google Chrome Version 103.0.5060.114 (Official Build) (64-bit)
Steps to attack:
- Login with user credentials.

- Go to the “Forum”(any forum) as show in the picture

- Next, click on the “Forum Subject” input then enter the XSS payload and press the Create Forum button then there will be a message saying that the forum has been successfully created as in the picture.


- Next, go back to the index.php page and you will see that a new forum has been created.

- After, go to that forum The XSS payload will run immediately.

Discoverer:
Grim The Ripper Team by SOSECURE Thailand
Reference:
메타데이터
- post_id
- a453789736f2
- slug
- klik-socialmediawebsite-version-1-0-1-stored-xss-vulnerability-at-forum-subject-a453789736f2
- url
- https://medium.com/@grimthereaperteam/klik-socialmediawebsite-version-1-0-1-stored-xss-vulnerability-at-forum-subject-a453789736f2
- canonical_url
- https://medium.com/@grimthereaperteam/klik-socialmediawebsite-version-1-0-1-stored-xss-vulnerability-at-forum-subject-a453789736f2
- author_url
- https://medium.com/@grimthereaperteam
- status
- ok
- fetched_at
- 2026-06-29 22:44:20