PT-2026-97053 · Unknown · Clipbucket
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
ClipBucket versions 5.x through 5.5.3-#181
Description
A reflected cross-site scripting issue exists in the
sort link() helper function. The application fails to properly sanitize the cat, sort, and time query parameters, allowing attackers to inject malicious script payloads. This can lead to the execution of arbitrary JavaScript in the browser of a victim under the application origin.Recommendations
Update ClipBucket to version 5.5.3-#182.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Clipbucket