Path Traversal Vulnerability in ClipBucket by MacWarrior
CVE-2025-62424
What is CVE-2025-62424?
ClipBucket, a web-based video-sharing platform, has a vulnerability in versions 5.5.2 - #146 and earlier, where the /admin_area/template_editor.php endpoint is susceptible to path traversal attacks. This occurs due to insufficient validation of file-loading paths, allowing authenticated administrators to manipulate the folder parameter to read and write files outside the designated template directory. An attacker with administrative access can exploit this vulnerability to access sensitive files like /etc/passwd and alter files on the server, risking the exposure of confidential data and potential compromise of the application.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
clipbucket-v5 < 5.5.2 - #147
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
