MacWarrior clipbucket-v5是MacWarrior的内容管理系统。 ClipBucket v5 5.5.3 - #141之前版本存在安全漏洞,该漏洞源于对SQL通配符字符的中和不当,可能导致经过身份验证的用户通过发送%字符作为number参数,在单个HTTP请求中覆盖其拥有的任何视频的所有字幕标题。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| MacWarrior | clipbucket-v5 | < 5.5.3 - #141 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| MacWarrior | clipbucket-v5 | < 5.5.3 - #141 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-42846 | 9.8 CRITICAL | ClipBucket: Remote Play URL Command Injection |
| CVE-2026-45060 | 9.8 CRITICAL | ClipBucket: Blind SQL Injection in progress_video.php |
| CVE-2026-45418 | 8.8 HIGH | ClipBucket: Blind SQL Injection in subtitle_edit.php |
| CVE-2026-47238 | 6.5 MEDIUM | ClipBucket: IDOR in videos subtitle editor |
No comments yet