PT-2025-42631 · Unknown · Clipbucket
Published
2025-10-17
·
Updated
2025-10-17
·
CVE-2025-62424
CVSS v3.1
6.7
Medium
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:L |
Name of the Vulnerable Software and Affected Versions
ClipBucket versions prior to 5.5.2 - #147
Description
ClipBucket is a web-based video-sharing platform. The
/admin area/template editor.php API endpoint has insufficient validation of the file-loading path. This allows administrators to read and write arbitrary files outside the intended template directory by using path traversal sequences in the folder parameter. An attacker with administrator privileges can read sensitive files, such as /etc/passwd, and modify writable files on the system, potentially leading to sensitive information disclosure and system compromise.Recommendations
Update to ClipBucket version 5.5.2 - #147 or later.
Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Clipbucket