---
id: CVE-2025-62423
title: ClipBucket V5 provides open source video hosting with PHP
summary: >-
  ClipBucket V5 provides open source video hosting with PHP. In version5.5.2 -
  #140 and earlier, a Blind SQL injection vulnerability exists in the Admin
  Area’s “/admin_area/login_as_user.php” file. Exploiting this vulnerability
  requires ac…
severity: medium
cvss: 6.7
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:L'
cwe:
  - CWE-89
vendor: oxygenz
product: clipbucket
affected:
  - 'clipbucket >= 5.3, < 5.5.2-142'
patched:
  - clipbucket 5.5.2-142
published: '2025-10-16'
updated: '2026-10-09'
sourceUpdated: '2026-10-09T10:10:00.193'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-62423'
references:
  - url: >-
      https://github.com/MacWarrior/clipbucket-v5/commit/b3bf27e367f318c2afe9bd11368be9d00e272148
    label: security-advisories@github.com
  - url: >-
      https://github.com/MacWarrior/clipbucket-v5/security/advisories/GHSA-3wpr-jprj-52fc
    label: security-advisories@github.com
  - url: >-
      https://github.com/MacWarrior/clipbucket-v5/security/advisories/GHSA-3wpr-jprj-52fc
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
epss: 0.00518
epssPercentile: 0.42224
ingestedAt: '2026-10-09T12:53:29.094Z'
---

## Overview

ClipBucket V5 provides open source video hosting with PHP. In version5.5.2 - #140 and earlier, a Blind SQL injection vulnerability exists in the Admin Area’s “/admin_area/login_as_user.php” file. Exploiting this vulnerability requires access privileges to the Admin Area.

## Affected

- `clipbucket >= 5.3, < 5.5.2-142`

## Remediation

Upgrade past the affected range:

- `clipbucket 5.5.2-142`
