Loading HuntDB...

CVE-2025-21624

CRITICAL
Published 2025-01-07T15:46:11.169Z
Actions:

Expert Analysis

Professional remediation guidance

Get tailored security recommendations from our analyst team for CVE-2025-21624. We'll provide specific mitigation strategies based on your environment and risk profile.

CVSS Score

V3.1
9.8
/10
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score Metrics
Exploitability: N/A Impact: N/A

EPSS Score

v2025.03.14
0.083
probability
of exploitation in the wild

There is a 8.3% chance that this vulnerability will be exploited in the wild within the next 30 days.

Updated: 2025-06-25
Exploit Probability
Percentile: 0.918
Higher than 91.8% of all CVEs

Attack Vector Metrics

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED

Impact Metrics

Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Description

ClipBucket V5 provides open source video hosting with PHP. Prior to 5.5.1 - 239, a file upload vulnerability exists in the Manage Playlist functionality of the application, specifically surrounding the uploading of playlist cover images. Without proper checks, an attacker can upload a PHP script file instead of an image file, thus allowing a webshell or other malicious files to be stored and executed on the server. This attack vector exists in both the admin area and low-level user area. This vulnerability is fixed in 5.5.1 - 239.

Available Exploits

No exploits available for this CVE.

Related News

No news articles found for this CVE.

Affected Products

Social Media Intelligence

Real-time discussions and threat intelligence from social platforms

3 posts
Reddit 2 weeks, 2 days ago
crstux
Exploit Payload

🔥 Top 10 Trending CVEs (22/09/2025) Here’s a quick breakdown of the 10 most interesting vulnerabilities trending today: **1. [CVE-2025-57822](https://nvd.nist.gov/vuln/detail/CVE-2025-57822)** - 📝 Next.js is a React framework for building full-stack web applications. Prior to versions 14.2.32 and 15.4.7, when next() was used without explicitly passing the request object, it could …

1
1.0
View Original High Risk
Reddit 2 weeks, 3 days ago
crstux
Exploit Payload

🔥 Top 10 Trending CVEs (21/09/2025) Here’s a quick breakdown of the 10 most interesting vulnerabilities trending today: **1. [CVE-2025-24054](https://nvd.nist.gov/vuln/detail/CVE-2025-24054)** - 📝 NTLM Hash Disclosure Spoofing Vulnerability - 📅 **Published:** 11/03/2025 - 📈 **CVSS:** 6.5 - 🧭 **Vector:** CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C - 📣 **Mentions:** 85 - ⚠️ **Priority:** {"error":"Priority not found for …

1
1.0
View Original High Risk
Reddit 2 weeks, 4 days ago
crstux
Exploit Payload

🔥 Top 10 Trending CVEs (20/09/2025) Here’s a quick breakdown of the 10 most interesting vulnerabilities trending today: **1. [CVE-2025-55241](https://nvd.nist.gov/vuln/detail/CVE-2025-55241)** - 📝 Azure Entra Elevation of Privilege Vulnerability - 📅 **Published:** 04/09/2025 - 📈 **CVSS:** 10 - 🧭 **Vector:** CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C - 📣 **Mentions:** 19 - ⚠️ **Priority:** 2 - 📝 …

1
1.0
View Original High Risk

References

Published: 2025-01-07T15:46:11.169Z
Last Modified: 2025-01-07T17:02:34.217Z
Copied to clipboard!