CVE-2018-7666

Severity CVSS v4.0:
Pending analysis
Type:
CWE-89 SQL Injection
Publication date:
05/03/2018
Last modified:
27/03/2018

Description

An issue was discovered in ClipBucket before 4.0.0 Release 4902. SQL injection vulnerabilities exist in the actions/vote_channel.php channelId parameter, the ajax/commonAjax.php email parameter, and the ajax/commonAjax.php username parameter.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:clip-bucket:clipbucket:*:*:*:*:*:*:*:* 4.0.0 (including)