Impact
ClipBucket v5 before 5.5.3-#182 contains a file upload flaw that allows an authenticated attacker to upload a file with a .php extension that passes MIME validation because the extension is not converted after validation. The uploaded file is stored on disk with the attacker‑controlled extension and executed by PHP‑FPM when accessed, enabling arbitrary PHP code execution.
Affected Systems
The affected product is ClipBucket v5, developed by MacWarrior. Versions prior to 5.5.3 installation using an older release remains vulnerable.
Risk and Exploitability
The CVSS base score of 8.7 indicates a high‑severity vulnerability. The EPSS score is < 1% and the issue is not listed in CISA KEV, though the attack requires valid application credentials. An authenticated attacker can gain full control of the server by uploading a malicious script and retrieving it, leading to complete compromise of confidentiality, integrity, and availability of the affected system.
OpenCVE Enrichment