GHSA-5vrm-rpx8-j2p7HighCVSS 7.2

ClipBucket v5 before 5.5.3-#197 contains a path traversal vulnerability in the admin template...

Published
September 25, 2026
Last Modified
September 25, 2026

🔗 CVE IDs covered (1)

📋 Description

ClipBucket v5 before 5.5.3-#197 contains a path traversal vulnerability in the admin template editor that allows authenticated administrators to overwrite PHP files by supplying directory traversal sequences in the folder parameter. Attackers with manage_template_access permission can traverse outside the layout directory to modify executable PHP files and achieve remote code execution as the web server user.

🔗 References (8)