CVE-2025-21622

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Jan 7, 2025
CWE ID 22

Summary

CVE-2025-21622 is a vulnerability affecting ClipBucket V5, an open-source video hosting solution built with PHP. During the user avatar upload and deletion process, ClipBucket checks for the avatar file path in the avatars directory before deleting it. However, there is no validation for path traversal sequences in the user-supplied avatar URL, stored in the database as avatar_url. This oversight enables an attacker to manipulate the file deletion process, leading to the deletion of files outside the intended scope of the avatars folder. The vulnerability is rectified in versions 5.5.1 and above, release 237.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share