Impact
ClipBucket v5 before 5.5.3-#182 contains a file upload flaw that allows an attacker who can authenticate to the application to upload a file with a .php extension that passes MIME validation because the extension is not converted after validation. The uploaded file is stored on disk with the attacker‑controlled extension and executed by PHP‑FPM when accessed, enabling arbitrary PHP code execution.
Affected Systems
The affected product is ClipBucket v5, developed by MacWarrior. Versions prior to 5.5.3-#182 are impacted; any installation using an older release remains vulnerable.
Risk and Exploitability
The CVSS base score of 8.7 indicates a high‑severity vulnerability. The EPSS score is not available and the issue is not listed in CISA KEV, though the attack requires valid application credentials. An authenticated attacker can gain full control of the server by uploading a malicious script and retrieving it, leading to complete compromise of confidentiality, integrity, and availability of the affected system.
OpenCVE Enrichment