high · CVSS v3 7.2 · CVSS v4 8.6
CVE-2026-103766
ClipBucket v5 and v5.5.3 are vulnerable to a SQL injection that can be triggered by authenticated users with ad_manager_access. The flaw all
Overview
ClipBucket v5 and v5.5.3 are vulnerable to a SQL injection that can be triggered by authenticated users with ad_manager_access. The flaw allows attackers to extract user credentials, emails, and modify or delete arbitrary database records. This can lead to data compromise and loss of integrity for the affected sites.
Description
ClipBucket v5 through 5.5.3-#197 contains an sql injection vulnerability that allows authenticated users with ad_manager_access permission to inject SQL via the delete parameter in admin_area/ads_manager.php. Attackers can supply time-based blind payloads concatenated into AdsManager::DeleteAd queries to extract user credentials and emails or modify and delete arbitrary records.
Impact
The vulnerability compromises confidentiality by exposing user credentials and emails. It also undermines integrity by allowing modification or deletion of arbitrary records. Availability is not directly affected, but the loss of data integrity can disrupt normal operations. Defenders should focus on protecting accounts with ad_manager_access.
Remediation
Apply the official patch that removes the vulnerable delete parameter handling in admin_area/ads_manager.php. If a patch is not yet available, disable the ad_manager_access permission for all users or restrict it to trusted administrators. Additionally, enforce parameterized queries and input validation for all database interactions. Monitor database logs for suspicious delete queries.
Risk context
The CVE is rated high with CVSS v3 of 7.2 and CVSS v4 of 8.6, indicating a significant risk to confidentiality and integrity. No EPSS data is available, but the high severity suggests that attackers could exploit this flaw quickly if they have authenticated access. Defenders should treat this as a priority to mitigate.
Affected products
- ClipBucket v5
- ClipBucket v5.5.3
Scores
- Severity
- high
- CVSS v2
- 8.3
- CVSS v3
- 7.2
- CVSS v4
- 8.6
- EPSS
- —