CVE-2025-21624

Published Jan 7, 2025

Last updated a month ago

CVSS critical 9.8
ClipBucket V5

Overview

AI description

Automated description summarized from trusted sources.

CVE-2025-21624 is a file upload vulnerability affecting ClipBucket V5, an open-source video hosting platform written in PHP. Specifically, versions prior to 5.5.1-239 are vulnerable. The vulnerability exists within the "Manage Playlist" functionality, particularly during the uploading of playlist cover images. Due to a lack of proper checks, an attacker can upload a PHP script file instead of a legitimate image file. This allows the attacker to store and execute a webshell or other malicious files on the server. The attack vector is present in both the admin and low-level user areas. Version 5.5.1-239 addresses and fixes this vulnerability.

Description
ClipBucket V5 provides open source video hosting with PHP. Prior to 5.5.1 - 239, a file upload vulnerability exists in the Manage Playlist functionality of the application, specifically surrounding the uploading of playlist cover images. Without proper checks, an attacker can upload a PHP script file instead of an image file, thus allowing a webshell or other malicious files to be stored and executed on the server. This attack vector exists in both the admin area and low-level user area. This vulnerability is fixed in 5.5.1 - 239.
Source
security-advisories@github.com
NVD status
Analyzed
Products
clipbucket

Risk scores

CVSS 3.1

Type
Secondary
Base score
9.8
Impact score
5.9
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity
CRITICAL

Weaknesses

security-advisories@github.com
CWE-434

Social media

Hype score
Not currently trending

Configurations