CVE-2026-102569
⚪ Do wiadomości
W ClipBucket występuje podatność na SQL injection, umożliwiająca administratorom modyfikację bazy danych.
CVSS
5.5
EPSS
0.2%
Exploit
none
Vendor
Opis źródłowy (NVD)
ClipBucket v5 through 5.5.3-#197 contains a time-based blind SQL injection vulnerability in the admin video edit function where the videoid parameter is concatenated into an UPDATE statement without proper escaping. An authenticated administrator with video_moderation permission can inject arbitrary SQL commands to extract or modify database contents.
sql-injection
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 5.5 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 0.2% |
| Opublikowano (NVD) | 2026-09-29 15:17:18 UTC |
| Ostatnia modyfikacja (NVD) | 2026-10-02 13:17:15 UTC |
Referencje
- https://github.com/MacWarrior/clipbucket-v5 ([email protected])
- https://github.com/MacWarrior/clipbucket-v5/blob/f15cef1a2431786c31ffd79e81f55d6eeca4ebc0/upload/includes/classes/video.class.php#L1972 ([email protected])
- https://github.com/MacWarrior/clipbucket-v5/commit/1c30d0b0e093ecfc656c98758707352abb2fc6ab ([email protected])
- https://hackmd.io/@leediay/two-blind-sqli-clickbucketv5-version_5_5_3_197 ([email protected])
- https://www.vulncheck.com/advisories/clipbucket-v5-through-5.5.3-197-sql-injection-via-videoid-parameter ([email protected])