CVE-2026-102569: ClipBucket v5 through 5.5.3-#197 SQL Injection via videoid Parameter
ClipBucket v5 through 5.5.3-#197 contains a time-based blind SQL injection vulnerability in the admin video edit function where the videoid parameter is concatenated into an UPDATE statement without proper escaping. An authenticated administrator with videomoderation permission can inject arbitrary SQL commands to extract or modify database contents.
Affected Software
Event History
Frequently Asked Questions
What level of access does an attacker need to exploit this issue?
The attacker must be authenticated as an administrator and have the video_moderation permission. Unauthenticated users and accounts without that permission are not described as able to exploit it.
What can an attacker do through this vulnerability?
An attacker meeting the permission requirement can use the videoid parameter to inject SQL through the admin video edit function. The described impact includes extracting database contents or modifying them.
How can I determine whether my deployment is affected?
Deployments running ClipBucket v5 through 5.5.3-#197 are identified as affected. The vulnerable code path is the administrative video edit function handling the videoid parameter.