CVE-2025-21623: ClipBucket V5 Unauthenticated Template Directory Update to Denial-of-Service
Published Jan 7, 2025
·Updated
ClipBucket V5 provides open source video hosting with PHP. Prior to 5.5.1 - 238, ClipBucket V5 allows unauthenticated attackers to change the template directory via a directory traversal, which results in a denial of service.
Affected Software
2 affected components
ClipBucket ClipBucket V5<5.5.1
Oxygenz Clipbucket>=5.3<5.5.1-238
Remediation
Event History
Jan 7, 2025
CVE Published
via MITRE·03:43 PM
Data Sourced
via MITRE·03:43 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-21623?
CVE-2025-21623 is considered to have a high severity due to its potential to cause denial of service.
2
How can I fix CVE-2025-21623?
To fix CVE-2025-21623, users should upgrade to ClipBucket V5 version 5.5.1 or later.
3
What is affected by CVE-2025-21623?
CVE-2025-21623 affects ClipBucket V5 versions prior to 5.5.1.
4
What type of attack does CVE-2025-21623 enable?
CVE-2025-21623 enables unauthenticated attackers to exploit directory traversal vulnerabilities.
5
What is the impact of CVE-2025-21623?
The impact of CVE-2025-21623 includes the ability to change the template directory, leading to a denial of service.