Exploitation Summary
EIP tracks 1 public exploit for CVE-2025-55912. PoCs published by Mukundsinh Solanki (r00td3str0y3r).
AI-analyzed exploit summary This exploit demonstrates an unauthenticated arbitrary file upload vulnerability in ClipBucket <= 5.5.0, allowing remote code execution via a crafted PHP file uploaded to `upload/actions/photo_uploader.php`.
Description
An issue in ClipBucket 5.5.0 and prior versions allows an unauthenticated attacker can exploit the plupload endpoint in photo_uploader.php to upload arbitrary files without any authentication, due to missing access controls in the upload handler
Exploits (1)
This exploit demonstrates an unauthenticated arbitrary file upload vulnerability in ClipBucket <= 5.5.0, allowing remote code execution via a crafted PHP file uploaded to `upload/actions/photo_uploader.php`.
References (4)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L