Impact
ClipBucket v5 releases before 5.5.3-#182 contain a blind SQL injection that can be triggered through the private message deletion endpoint. An authenticated user can submit the msg_id parameter as an array to bypass the clean_requests() sanitization, and the unescaped array element is placed directly into a SQL query by the delete_msg() method. The vulnerability allows time‑based blind SQL injection, enabling extraction of any data stored in the database such as user credential hashes and email addresses.
Affected Systems
It affects the ClipBucket v5 platform distributed by MacWarrior, specifically all installations running versions earlier than 5.5.3‑#182. The vulnerable code resides in private_message.php and ClipBucket.class.php. No other products or vendors are listed.
Risk and Exploitability
The CVSS score of 7.1 reflects a medium‑high severity risk for the affected systems, with an EPSS score of <1% and no listing in the CISA KEV catalog. Exploitation requires a valid authenticated session, so attackers with access to a user account or compromised credentials can launch the attack. The injection occurs through a legitimate deletion API, making it hard to detect and potentially allowing full database compromise over time. Because the exploit relies on authenticated users, an internal or compromised user can serve as the entry point.
OpenCVE Enrichment