Sceawere
Vulnerability Detail
CVE-2026-103766UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
ClipBucket SQL Injection Vulnerability
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.2
- Creation Date
- 23h ago
- Vendor
- MacWarrior
- Product
- clipbucket-v5
- Attack Type
- Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
ClipBucket v5 through 5.5.3-#197 contains an sql injection vulnerability that allows authenticated users with ad_manager_access permission to inject SQL via the delete parameter in admin_area/ads_manager.php. Attackers can supply time-based blind payloads concatenated into AdsManager::DeleteAd queries to extract user credentials and emails or modify and delete arbitrary records.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.2",
"pubDate": "2026-10-02T00:16:59.820Z",
"pubdate": "2026-10-02T00:16:59.820Z",
"executiveSummary": "This vulnerability is an authenticated SQL injection flaw residing within the ClipBucket v5 through 5.5.3-#197 content management system. The vulnerability exists within the ad_manager_access functionality of the administrative interface, specifically triggered via the delete parameter in admin_area/ads_manager.php.\nThe flaw allows an authenticated attacker possessing the ad_manager_access privilege to execute arbitrary SQL commands by injecting malicious payloads into the AdsManager::DeleteAd function. Because the input supplied to the delete parameter is not adequately sanitized before being concatenated into database queries, the application is susceptible to time-based blind SQL injection attacks.\nSuccessful exploitation grants an attacker the ability to interact directly with the underlying backend database. This capability allows for the unauthorized extraction of sensitive information, including user credentials and email addresses. Furthermore, an attacker may leverage this vulnerability to modify or delete arbitrary records within the database, potentially leading to full compromise of the application data integrity and administrative control. Given the requirement for specific administrative permissions, this vulnerability represents a significant escalation risk for compromised or malicious insider accounts, necessitating immediate patching or input restriction protocols.",
"technicalDetails": "The vulnerability is rooted in improper input validation and the use of dynamic SQL query construction within the AdsManager::DeleteAd method. The application fails to utilize parameterized queries or prepared statements when processing the delete parameter, which is passed from the admin_area/ads_manager.php file.\nWhen a user with ad_manager_access submits a request to the AdsManager module, the input provided to the delete parameter is treated as trusted data. An attacker can craft a malicious request containing SQL injection payloads, specifically leveraging time-based blind SQL techniques. By injecting conditional sleep commands (e.g., SLEEP() or BENCHMARK()), the attacker can infer data bit-by-bit by observing the response latency of the server. This bypasses the need for the application to return direct database output to the browser.\nThe exploitation flow proceeds as follows: First, the attacker authenticates as a user with the ad_manager_access permission level. Second, the attacker intercepts the HTTP request triggered by the deletion of an advertisement within the administrative console. Third, the attacker appends the malicious SQL payload to the delete parameter. The backend engine processes the concatenated string, executing the injected logic as part of the intended AdsManager::DeleteAd database operation.\nThis vulnerability permits the attacker to execute arbitrary queries, enabling the exfiltration of the entire database schema, user tables containing hashed passwords, and session tokens. Furthermore, the attacker can execute data manipulation commands such as UPDATE or DELETE, which could be used to escalate privileges, disable security audits, or clear logs. Because the application logic relies on the unchecked parameter in the SQL query string, the database management system (DBMS) interprets the injected malicious syntax as legitimate instructions.\nThe affected versions include ClipBucket v5 through 5.5.3-#197. The requirement for ad_manager_access restricts the attack surface to authenticated administrative or privileged accounts, but this serves as a critical threat to multi-user environments or instances where administrative credentials may have been partially compromised. The vulnerability is persistent across the codebase where the affected AdsManager class methods are invoked without input filtering, allowing for systematic database probing and subsequent impact on the confidentiality, integrity, and availability of the application."
}