PT-2025-45407 · Unknown · Clipbucket
Published
2025-11-07
·
Updated
2025-12-05
·
CVE-2025-64336
CVSS v4.0
8.6
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
ClipBucket versions 5.5.2-#146 and below
Description
ClipBucket is a video sharing platform. A stored Cross-site Scripting (XSS) issue exists in the Manage Photos feature. An authenticated regular user can upload a photo with a malicious Photo Title containing HTML/JavaScript code. This code is rendered unsafely in the Admin → Manage Photos section, leading to JavaScript execution in the administrator’s browser. The
Photo Title is the vulnerable parameter.Recommendations
Update to ClipBucket version 5.5.2-#147.
Exploit
Fix
Improper Privilege Management
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Clipbucket