PT-2025-42631 · Unknown · Clipbucket

Published

2025-10-17

·

Updated

2025-10-17

·

CVE-2025-62424

CVSS v3.1

6.7

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:L
Name of the Vulnerable Software and Affected Versions ClipBucket versions prior to 5.5.2 - #147
Description ClipBucket is a web-based video-sharing platform. The /admin area/template editor.php API endpoint has insufficient validation of the file-loading path. This allows administrators to read and write arbitrary files outside the intended template directory by using path traversal sequences in the folder parameter. An attacker with administrator privileges can read sensitive files, such as /etc/passwd, and modify writable files on the system, potentially leading to sensitive information disclosure and system compromise.
Recommendations Update to ClipBucket version 5.5.2 - #147 or later.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-62424
GHSA-3V2P-RFWX-52QJ

Affected Products

Clipbucket