Sceawere
Vulnerability Detail
CVE-2026-102569UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
ClipBucket SQL Injection Vulnerability
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 5.5
- Creation Date
- 10h ago
- Vendor
- MacWarrior
- Product
- clipbucket-v5
- Attack Type
- Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
ClipBucket v5 through 5.5.3-#197 contains a time-based blind SQL injection vulnerability in the admin video edit function where the videoid parameter is concatenated into an UPDATE statement without proper escaping. An authenticated administrator with video_moderation permission can inject arbitrary SQL commands to extract or modify database contents.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "5.5",
"pubDate": "2026-09-29T15:17:18.757Z",
"pubdate": "2026-09-29T15:17:18.757Z",
"executiveSummary": "ClipBucket versions 5 through 5.5.3-#197 are susceptible to a time-based blind SQL injection vulnerability located within the administrative video editing functionality.\nThe vulnerability originates from improper neutralization of user-supplied data, specifically the 'videoid' parameter, before incorporating it into an UPDATE SQL statement.\nSuccessful exploitation allows an authenticated administrator possessing 'video_moderation' privileges to execute arbitrary SQL queries against the underlying database.\nThis vulnerability carries significant security implications, as it enables unauthorized actors to perform data exfiltration, database modification, or compromise the integrity of the application's backend repository.\nBecause the vulnerability is time-based, an attacker can infer database content by observing the latency in server responses to crafted SQL payloads that induce artificial delays.\nThe attack necessitates a baseline level of administrative access, limiting the scope to authenticated users with specific moderation permissions, yet representing a critical escalation of privilege for malicious insiders or compromised administrative accounts.",
"technicalDetails": "The vulnerability resides in the admin video edit function of ClipBucket, where the application fails to sanitize or parameterize input provided via the 'videoid' parameter. This parameter is directly concatenated into an SQL UPDATE query intended to modify video metadata. The lack of parameterized queries or robust input validation mechanisms allows for the injection of arbitrary SQL commands.\nThe primary attack vector involves manipulating the 'videoid' parameter to include malicious SQL syntax. As a time-based blind SQL injection, the attacker does not receive direct output from the query. Instead, the attacker crafts payloads leveraging conditional logic—such as 'IF' statements or time-delay functions like 'SLEEP()' or 'BENCHMARK()'—that trigger a temporal delay in the application's response only if a specific query condition evaluates to true.\nThe attack flow proceeds as follows: First, the attacker authenticates as an administrator with the required 'video_moderation' permissions. Second, the attacker intercepts the request to the video edit interface and injects a payload into the 'videoid' parameter. An example payload might look like: '123 AND (SELECT 1 FROM (SELECT(SLEEP(5)))a)'.\nWhen the server processes this input, the database engine executes the injected 'SLEEP' command if the preceding conditions are met. By measuring the elapsed time before the server sends a response, the attacker can verify the veracity of the injected query. Through iterative testing, the attacker can enumerate database structures, extract sensitive configuration data, retrieve administrative credentials, or manipulate records within the database tables.\nThe root cause is the reliance on insecure string concatenation for dynamic SQL construction, which bypasses the database's query abstraction layers. This vulnerability affects all ClipBucket versions from 5.0 through 5.5.3-#197. Given that the vulnerable component is an administrative module, the impact is severe, potentially leading to a complete compromise of the platform's data layer if an attacker successfully gains access to an account with the necessary, albeit restricted, moderation privileges. The absence of input sanitization at the application layer leaves the database vulnerable to unauthorized data manipulation and full-scale information disclosure via inference."
}