Open Source Video Sharing Platform Vulnerability in ClipBucket by MacWarrior
CVE-2025-62709
6.8MEDIUM
What is CVE-2025-62709?
ClipBucket v5.5.2, an open source video sharing platform, is susceptible to a vulnerability that alters the server URL based on the user-controlled HTTP Host header when the base_url configuration is unset. An attacker can manipulate this header to issue malicious password-reset links via forget.php. If the victim interacts with these links and submits their activation code on a spoofed domain, the attacker captures the activation code, enabling them to reset the victim's password and gain unauthorized access to their account. This critical issue has been addressed in a security patch released for version 5.5.2#162.
Affected Version(s)
clipbucket-v5 >= 5.5.2, < 5.5.2#162
