Impact
ClipBucket v5 prior to release 5.5.3‑#182 contains a blind SQL injection flaw in the photo deletion endpoint. The vulnerability allows an authenticated user to submit an array value for the check_photo parameter, which bypasses the internal clean_requests() sanitisation routine. The unsanitised array elements reach the photo_exists() routine, where non‑numeric values are interpolated directly into a SQL query, enabling time‑based blind injection. Attackers can therefore extract arbitrary database contents, including credential hashes and other sensitive data, without needing to exploit the application in a user‑friendly manner.
Affected Systems
The flaw affects installations of ClipBucket v5 from MacWarrior, specifically versions earlier than 5.5.3‑#182. Any system running this version and allowing authenticated users to access the bulk deletion handler in manage_photos.php is at risk. No other products or versions have been identified as impacted.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity data‑exfiltration risk. The EPSS score of 0.00406 indicates a very low likelihood of immediate exploitation, and the vulnerability is not listed in CISA’s KEV catalog. The attack requires authenticated access to the photo deletion endpoint, which is likely restricted to registered users. Once accessed, an attacker can inject arbitrary arrays to perform blind SQLi, exploiting the lack of parameterised queries and allowing information disclosure. The absence of a public exploit does not reduce the need for a timely update because the conditions for exploitation are realistic and the impact is significant.
OpenCVE Enrichment