Back to Database
Status published
Medium
CVE-2025-62423
ClipBucket V5 Blind SQL injection in the Admin Panel
Vulnerability Description
ClipBucket V5 provides open source video hosting with PHP. In version5.5.2 - #140 and earlier, a Blind SQL injection vulnerability exists in the Admin Area’s “/admin_area/login_as_user.php” file. Exploiting this vulnerability requires access privileges to the Admin Area.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-62423
Credits & Attribution
No credits recorded in the NVD database.
References
More from MacWarrior
View All →CVE-2025-65113
ClipBucket v5 Unauthenticated Object Flagging Vulnerability
Medium
6.5
CVE-2025-64339
ClipBucket v5: Stored XSS Vulnerability in Manage Playlists
High
7.2
CVE-2025-64338
ClipBucket's Manage Photos Feature is Vulnerable to Stored XSS via Collection Name
Medium
5.1
CVE-2025-64336
ClipBucket v5's Manage Photo Feature is Vulnerable to Stored XSS Attack via Photo Title
High
7.2
CVE-2025-64114
ClipBucket v5: SQL Injection possible through ClipBucket Custom Fields plugin
Medium
6.5
Affected Vendor
MacWarrior
View all reports →Affected Software
clipbucket-v5
Vulnerable Versions:
<= 5.5.2 - #140
Timeline
Official Publish:
October 16th, 2025
Last Modified:
October 17th, 2025
Added to House:
July 22nd, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:L