CVE-2025-55912: Malicious File Upload
An issue in ClipBucket 5.5.0 and prior versions allows an unauthenticated attacker can exploit the plupload endpoint in photouploader.php to upload arbitrary files without any authentication, due to missing access controls in the upload handler
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2025-55912?
CVE-2025-55912 has a high severity due to the potential for unauthenticated file uploads by attackers.
How do I fix CVE-2025-55912?
To fix CVE-2025-55912, upgrade ClipBucket to the latest version beyond 5.5.0, ensuring proper access controls are enforced.
What versions of ClipBucket are affected by CVE-2025-55912?
CVE-2025-55912 affects ClipBucket version 5.5.0 and prior versions.
What type of attack does CVE-2025-55912 enable?
CVE-2025-55912 enables unauthorized file uploads by allowing unauthenticated users to exploit the plupload endpoint.
How can CVE-2025-55912 impact my system?
CVE-2025-55912 can allow attackers to upload arbitrary files, potentially leading to security breaches or server compromise.