GHSA-h7wf-mrfw-7fxqCriticalCVSS 9.8

ClipBucket V5's web installer fails to properly validate or escape the php_cli_filepath parameter...

Published
August 26, 2026
Last Modified
August 26, 2026

🔗 CVE IDs covered (1)

📋 Description

ClipBucket V5's web installer fails to properly validate or escape the php_cli_filepath parameter before passing it to shell execution. Unauthenticated attackers can submit a crafted POST request to the installer with a malicious php_cli_filepath value to execute arbitrary commands as the web server user.

🔗 References (7)