PT-2026-95394 · Unknown · Clipbucket

·

CVE-2026-77928

·

Published

2026-09-18

·

Updated

2026-09-18

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions ClipBucket versions prior to 5.5.3-#182
Description Authenticated users can extract arbitrary database contents, including user credential hashes and email addresses, through a time-based blind SQL injection. This occurs when the msg id parameter is submitted as an array to bypass the clean requests() sanitization function in ClipBucket.class.php. The unsanitized array elements are passed through the deletion handler in 'private message.php' into the cb pm::delete msg() function, which interpolates the unescaped message ID directly into a SQL query string.
Recommendations Update ClipBucket to version 5.5.3-#182 or later. As a temporary mitigation, restrict access to the 'private message.php' handler or avoid using the msg id parameter until the update is applied.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-77928

Affected Products

Clipbucket