CVE-2026-100372
Descriptive record received from OpenCTI and minimised for consultation in the Intel portal.
- Sharing
- PUBLIC-OSINT
- Confidence
- 100
- Source
- The CVE Program
- Updated
- 26/09/2026 04:28
Description
ClipBucket v5 before 5.5.3-#197 contains a path traversal vulnerability in the admin template editor that allows authenticated administrators to overwrite PHP files by supplying directory traversal sequences in the folder parameter. Attackers with manage_template_access permission can traverse outside the layout directory to modify executable PHP files and achieve remote code execution as the web server user.
Aliases and classifications
Minimised technical details
No raw data- cisa kev
- False
- cvss score
- 7.2
- cvss vector
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
- cvss severity
- HIGH
Public references
- patch
https://github.com/MacWarrior/clipbucket-v5/commit/f31de49b2194482ffef7147aa1e9b1c8f0f04eb7 - technical-description
https://github.com/MacWarrior/clipbucket-v5/blob/61cce55ab26ef88fb782dfde47b44c17c56978cd/upload/admin_area/template_editor.php - clipbucket-v5 5.5.3-%23197 Release Notes
https://github.com/MacWarrior/clipbucket-v5/releases/tag/5.5.3-%23197 - product
https://github.com/MacWarrior/clipbucket-v5 - VulnCheck Advisory: ClipBucket v5 before 5.5.3-#197 Path Traversal via template_editor.php
https://www.vulncheck.com/advisories/clipbucket-v5-before-5.5.3-197-path-traversal-via-template-editor-php - exploit
https://hackmd.io/@leediay/S1AIRjzqfx
Intel catalogue
The vulnerability is also available in the EudorIA editorial catalogue.
Open EudorIA analysisPresence in OpenCTI describes an intelligence correlation and does not, by itself, constitute evidence of compromise, legal attribution or operational guidance applicable without context verification.