PT-2026-95394 · Unknown · Clipbucket
CVSS v4.0
7.1
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
ClipBucket versions prior to 5.5.3-#182
Description
Authenticated users can extract arbitrary database contents, including user credential hashes and email addresses, through a time-based blind SQL injection. This occurs when the
msg id parameter is submitted as an array to bypass the clean requests() sanitization function in ClipBucket.class.php. The unsanitized array elements are passed through the deletion handler in 'private message.php' into the cb pm::delete msg() function, which interpolates the unescaped message ID directly into a SQL query string.Recommendations
Update ClipBucket to version 5.5.3-#182 or later.
As a temporary mitigation, restrict access to the 'private message.php' handler or avoid using the
msg id parameter until the update is applied.Exploit
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Clipbucket