ClipBucket v5 through 5.5.3-#197 contains a time-based blind SQL injection vulnerability in the admin video edit function where the videoid parameter is concatenated into an UPDATE statement without proper escaping. An authenticated administrator with video_moderation permission can inject arbitrary SQL commands to extract or modify database contents.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 29 Sep 2026 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | ClipBucket v5 through 5.5.3-#197 contains a time-based blind SQL injection vulnerability in the admin video edit function where the videoid parameter is concatenated into an UPDATE statement without proper escaping. An authenticated administrator with video_moderation permission can inject arbitrary SQL commands to extract or modify database contents. | |
| Title | ClipBucket v5 through 5.5.3-#197 SQL Injection via videoid Parameter | |
| First Time appeared |
Clip-bucket
Clip-bucket clipbucket |
|
| Weaknesses | CWE-89 | |
| CPEs | cpe:2.3:a:clip-bucket:clipbucket:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Clip-bucket
Clip-bucket clipbucket |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-29T14:22:38.040Z
Reserved: 2026-09-29T13:43:15.671Z
Link: CVE-2026-102569
No data.
Status : Received
Published: 2026-09-29T15:17:18.757
Modified: 2026-09-29T15:17:18.757
Link: CVE-2026-102569
No data.
OpenCVE Enrichment
No data.
Weaknesses