PT-2025-47603 · Unknown · Clipbucket
Published
2025-11-20
·
Updated
2025-11-21
·
CVE-2025-62709
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
ClipBucket versions prior to 5.5.2#162
Description
ClipBucket is a video sharing platform. A flaw in version 5.5.2 allows an attacker to control the server URL due to a dynamic build from the HTTP Host header when the base url configuration is not set. This enables an attacker to manipulate password-reset links generated by the
forget.php script, causing them to point to the attacker’s domain. If a victim follows the malicious link and enters their activation code on the attacker’s domain, the attacker can capture the code and reset the victim’s password, leading to account takeover. The vulnerable component is network.class.php. The application builds the server URL from the client-controlled Host header.Recommendations
Update to ClipBucket version 5.5.2#162 or later.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Clipbucket