Описание
ClipBucket V5 provides open source video hosting with PHP. Prior to 5.5.1 - 239, a file upload vulnerability exists in the Manage Playlist functionality of the application, specifically surrounding the uploading of playlist cover images. Without proper checks, an attacker can upload a PHP script file instead of an image file, thus allowing a webshell or other malicious files to be stored and executed on the server. This attack vector exists in both the admin area and low-level user area. This vulnerability is fixed in 5.5.1 - 239.
Ссылки
- Patch
- ExploitVendor Advisory
- ExploitVendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия от 5.3 (включая) до 5.5.1-239 (исключая)
cpe:2.3:a:oxygenz:clipbucket:*:*:*:*:*:*:*:*
EPSS
Процентиль: 96%
0.23017
Средний
9.8 Critical
CVSS3
Дефекты
CWE-434
EPSS
Процентиль: 96%
0.23017
Средний
9.8 Critical
CVSS3
Дефекты
CWE-434