Description
ClipBucket v5 is an open source video sharing platform. Prior to version 5.5.3 - #141, ClipBucket v5 contains an improper neutralization of SQL wildcard characters in the subtitle editing endpoint. An authenticated user can send a % character as the number parameter to overwrite all subtitle titles of any video they own in a single HTTP request. This issue has been patched in version 5.5.3 - #141.
Problem types
CWE-155: Improper Neutralization of Wildcards or Matching Symbols
CWE-943: Improper Neutralization of Special Elements in Data Query Logic
Product status
References
github.com/...ket-v5/security/advisories/GHSA-wv43-277p-737c
github.com/...ket-v5/security/advisories/GHSA-wv43-277p-737c