Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-21624

Опубликовано: 07 янв. 2025
Источник: nvd
CVSS3: 9.8
EPSS Средний

Описание

ClipBucket V5 provides open source video hosting with PHP. Prior to 5.5.1 - 239, a file upload vulnerability exists in the Manage Playlist functionality of the application, specifically surrounding the uploading of playlist cover images. Without proper checks, an attacker can upload a PHP script file instead of an image file, thus allowing a webshell or other malicious files to be stored and executed on the server. This attack vector exists in both the admin area and low-level user area. This vulnerability is fixed in 5.5.1 - 239.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:oxygenz:clipbucket:*:*:*:*:*:*:*:*
Версия от 5.3 (включая) до 5.5.1-239 (исключая)

EPSS

Процентиль: 96%
0.23017
Средний

9.8 Critical

CVSS3

Дефекты

CWE-434

EPSS

Процентиль: 96%
0.23017
Средний

9.8 Critical

CVSS3

Дефекты

CWE-434