CVE-2026-102570
Received Received - Intake

Time-Based Blind SQL Injection in ClipBucket

Vulnerability report for CVE-2026-102570, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-29

Last updated on: 2026-09-29

Assigner: VulnCheck

Description

ClipBucket v5 through 5.5.3-#197 contains a time-based blind SQL injection vulnerability in the language update function where the language_id parameter is concatenated unescaped into the WHERE clause of an UPDATE statement. An authenticated administrator with basic_settings permission can inject arbitrary SQL payloads to extract or modify database contents.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-29
Last Modified
2026-09-29
Generated
2026-09-29
AI Q&A
2026-09-29
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
clipbucket clipbucket From 5 (inc) to 5.5.3-197 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-89 The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

ClipBucket v5 through 5.5.3-#197 has a time-based blind SQL injection vulnerability in the language update function. The language_id parameter is concatenated unescaped into the WHERE clause of an UPDATE statement. An authenticated administrator with basic_settings permission can inject arbitrary SQL payloads to extract or modify database contents.

Detection Guidance

To detect this vulnerability, check for suspicious SQL queries targeting the language update function in ClipBucket. Monitor database logs for time-based blind SQL injection patterns, such as delayed responses when injecting time delays like SLEEP(5) in the language_id parameter. Review access logs for unusual administrator activity in the language management section.

Impact Analysis

An attacker with admin access could exploit this to steal sensitive data, modify database records, or perform unauthorized actions. The impact includes potential data breaches, integrity compromise, and unauthorized system access.

Compliance Impact

This vulnerability could lead to unauthorized data access or modification, violating GDPR's data protection requirements and HIPAA's integrity and confidentiality rules. Non-compliance risks include fines, legal penalties, and reputational damage.

Mitigation Strategies

Immediately update ClipBucket to the latest patched version or apply the security fix by modifying upload/includes/classes/lang.class.php to use $lang['language_id'] instead of $array['language_id'] in the language update function. Restrict administrator access to basic_settings permissions and monitor for unauthorized database modifications.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-102570. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart