Open Source Video Sharing Platform Vulnerability in ClipBucket by MacWarrior
CVE-2025-62709

6.8MEDIUM

Key Information:

Vendor

Macwarrior

Vendor
CVE Published:
20 November 2025

What is CVE-2025-62709?

ClipBucket v5.5.2, an open source video sharing platform, is susceptible to a vulnerability that alters the server URL based on the user-controlled HTTP Host header when the base_url configuration is unset. An attacker can manipulate this header to issue malicious password-reset links via forget.php. If the victim interacts with these links and submits their activation code on a spoofed domain, the attacker captures the activation code, enabling them to reset the victim's password and gain unauthorized access to their account. This critical issue has been addressed in a security patch released for version 5.5.2#162.

Affected Version(s)

clipbucket-v5 >= 5.5.2, < 5.5.2#162

References

CVSS V3.1

Score:
6.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-62709 : Open Source Video Sharing Platform Vulnerability in ClipBucket by MacWarrior