Sceawere

Vulnerability Detail

CVE-2026-102570UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

ClipBucket SQL Injection Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.5
Creation Date
10h ago
Vendor
MacWarrior
Product
clipbucket-v5
Attack Type
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Vector String
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

ClipBucket v5 through 5.5.3-#197 contains a time-based blind SQL injection vulnerability in the language update function where the language_id parameter is concatenated unescaped into the WHERE clause of an UPDATE statement. An authenticated administrator with basic_settings permission can inject arbitrary SQL payloads to extract or modify database contents.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.5",
  "pubDate": "2026-09-29T15:17:18.917Z",
  "pubdate": "2026-09-29T15:17:18.917Z",
  "executiveSummary": "ClipBucket versions 5 through 5.5.3-#197 are susceptible to a time-based blind SQL injection vulnerability within the language update function.\nThis vulnerability stems from improper input sanitization, where the 'language_id' parameter is concatenated directly into an UPDATE statement without adequate escaping.\nSuccessful exploitation allows an authenticated administrator with 'basic_settings' permissions to execute arbitrary SQL queries against the underlying database.\nThe risk implication is significant, as it enables unauthorized access to sensitive application data, potential modification of database contents, and escalation of influence over the database environment.\nThe attack is characterized as a time-based blind injection, meaning attackers can infer information by measuring the time taken for the server to respond to crafted payloads.\nThe exploitation requirement is restricted to authenticated users holding administrative privileges, specifically those with access to the language management settings.\nThis vulnerability facilitates data exfiltration and potential compromise of the administrative interface and database integrity.",
  "technicalDetails": "The root cause of this vulnerability is an insecure implementation of data handling within the ClipBucket application's language update functionality. Specifically, the 'language_id' parameter, which is intended to identify a specific language entry in the database, is passed through the application logic without being subjected to parameterized queries or sufficient input validation.\nThe vulnerability resides in the backend logic responsible for processing updates to language settings. When an administrator submits an update request, the application constructs an SQL UPDATE query by concatenating the unescaped 'language_id' parameter directly into the WHERE clause of the statement.\nBecause the input is not sanitized or bound to a query parameter, an attacker can manipulate the structure of the SQL query. By injecting SQL control characters and commands, an attacker can append conditional logic that forces the database engine to pause or sleep if the injected condition is true.\nThe exploitation method relies on time-based blind SQL injection techniques. The attacker sends a series of crafted 'language_id' values containing payloads such as 'AND (SELECT 1 FROM (SELECT(SLEEP(5)))a)--'. If the condition is met, the database engine executes the sleep command, causing a measurable delay in the server's HTTP response. By iterating through this logic, the attacker can systematically extract information from the database, such as table names, column names, or user credentials, one bit or byte at a time.\nThe attack flow proceeds as follows: First, the authenticated attacker navigates to the language update interface. Second, the attacker intercepts the HTTP request and modifies the 'language_id' parameter to include the malicious SQL payload. Third, the server processes the request and executes the modified query against the database. Finally, the attacker observes the server's response time to infer the database contents.\nAffected versions include ClipBucket 5 through 5.5.3-#197. Exploitation requires the attacker to possess an authenticated session with 'basic_settings' privileges, significantly limiting the attack surface to malicious insiders or compromised administrative accounts. The potential impact extends to full database read/write access, depending on the permissions of the database user account utilized by the ClipBucket application."
}
CVE-2026-102570: ClipBucket SQL Injection Vulnerability (MEDIUM Severity, CVSS: 5.5) | Sceawere