Goal Reached Thanks to every supporter โ€” we hit 100%!

Goal: 1000 CNY ยท Raised: 1359 CNY

100%

CVE-2026-21875 โ€” AI Deep Analysis Summary

CVSS 9.8 ยท Critical

Q1What is this vulnerability? (Essence + Consequences)

๐Ÿšจ **Essence**: Blind SQL Injection in ClipBucket v5.5.2-#187 and earlier. <br>๐Ÿ“‰ **Consequences**: Attackers can extract database content via the `/actions/ajax.php` endpoint.โ€ฆ

Q2Root Cause? (CWE/Flaw)

๐Ÿ›ก๏ธ **Root Cause**: CWE-89 (SQL Injection). <br>โŒ **Flaw**: The `obj_id` parameter in `/actions/ajax.php` is **not validated or sanitized**. Malicious input bypasses security checks directly.

Q3Who is affected? (Versions/Components)

๐Ÿ“ฆ **Affected**: MacWarrior's **ClipBucket v5**. <br>๐Ÿ“… **Version**: Specifically **5.5.2-#187** and all prior versions. <br>๐ŸŒ **Type**: Open-source PHP script for video sharing sites.

Q4What can hackers do? (Privileges/Data)

๐Ÿ’€ **Attacker Capabilities**: <br>๐Ÿ”“ **Access**: Full database read/write potential. <br>๐Ÿ‘‘ **Privileges**: High (CVSS H).โ€ฆ

Q5Is exploitation threshold high? (Auth/Config)

๐Ÿ”“ **Threshold**: **LOW**. <br>๐Ÿšซ **Auth**: No authentication required (`PR:N`). <br>๐ŸŒ **Network**: Remote exploitation (`AV:N`). <br>๐Ÿ‘€ **UI**: No user interaction needed (`UI:N`). Easy to exploit!

Q6Is there a public Exp? (PoC/Wild Exploitation)

๐Ÿšซ **Public Exploit**: **None listed** in current data (`pocs: []`). <br>โš ๏ธ **Status**: While no public PoC is attached, the vulnerability type (Blind SQLi) is well-known. Exploitation tools likely exist in the wild.

Q7How to self-check? (Features/Scanning)

๐Ÿ” **Self-Check**: <br>1. Scan for `/actions/ajax.php` endpoint. <br>2. Test `obj_id` parameter with SQL injection payloads (e.g., `' OR 1=1--`). <br>3. Look for time-based delays or error responses indicating Blind SQLi.

Q8Is it fixed officially? (Patch/Mitigation)

โœ… **Fix Status**: **Yes**. <br>๐Ÿ”— **Source**: Official GitHub Advisory [GHSA-crpv-fmc4-j392](https://github.com/MacWarrior/clipbucket-v5/security/advisories/GHSA-crpv-fmc4-j392).โ€ฆ

Q9What if no patch? (Workaround)

๐Ÿ›ก๏ธ **No Patch Workaround**: <br>1. **WAF**: Block SQL keywords in `obj_id` parameter. <br>2. **Input Validation**: Strictly whitelist integer values for `obj_id`. <br>3.โ€ฆ

Q10Is it urgent? (Priority Suggestion)

๐Ÿ”ฅ **Urgency**: **CRITICAL**. <br>๐Ÿ“ˆ **CVSS**: High (9.8/10 implied by H/I/H). <br>โšก **Priority**: Patch immediately. Remote, unauthenticated exploitation makes this a high-priority target for attackers.