PT-2025-31538 · Clipbucket · Clipbucket

CVE-2013-10040

·

Published

2025-07-31

·

Updated

2025-09-23

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ClipBucket versions prior to 2.7
Description The software contains a critical issue in the ofc upload image.php script, located at the /admin area/charts/ofc-library/ endpoint. This allows unauthenticated users to upload arbitrary files, including executable PHP scripts. After uploading, an attacker can access the file through a predictable path and trigger remote code execution. The ofc upload image.php script is the component affected.
Recommendations Update to version 2.7 or later. As a temporary workaround, restrict access to the ofc upload image.php script.

Exploit

Fix

RCE

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2013-10040

Affected Products

Clipbucket