Impact
Authenticated users with ad_manager_access permission can supply arbitrary SQL code via the delete parameter in admin_area/ads_manager.php, which is directly concatenated into the AdsManager::DeleteAd queries. The vulnerability allows attackers to read user credentials and emails, modify or delete records, and generally tamper with the database.
Affected Systems
The affected product is ClipBucket version 5 and all releases up to 5.5.3-#197, distributed by MacWarrior. These versions use the oxygenz:clipbucket platform, and any installation within this version range must be assessed for the vulnerability.
Risk and Exploitability
The CVSS score of 8.6 marks a high severity, while no EPSS data is available and the issue is not yet listed in the CISA KEV catalog. Attackers require legitimate access with ad_manager_access privileges, but the time‑based blind injection technique can be used to exfiltrate data or alter database contents. The lack of an EPSS score suggests limited public exploitation at this time, but the high CVSS indicates a serious risk if exploited.
OpenCVE Enrichment