Skip to main content
Vulnerability Database/CVE-2025-64114

CVE-2025-64114: Oxygenz ClipBucket SQL Injection Vulnerability

CVE-2025-64114 is a SQL injection flaw in Oxygenz ClipBucket that allows authenticated administrators to execute arbitrary SQL commands. This post explains its impact, affected versions, and mitigation steps.

Published:

CVE-2025-64114 Overview

CVE-2025-64114 is an authenticated SQL injection vulnerability in ClipBucket v5, an open source video sharing platform maintained by Oxygenz. The flaw resides in the ClipBucket Custom Fields plugin and affects versions 5.5.2 - #151 and below. Administrators with plugin management privileges can execute arbitrary SQL commands against the backend database through the plugin interface. The issue is tracked under [CWE-89] (Improper Neutralization of Special Elements used in an SQL Command) and is addressed in release 5.5.2 - #152.

Critical Impact

Authenticated administrators with access to the Custom Fields plugin can read, modify, or delete arbitrary database records, compromising the confidentiality and integrity of all ClipBucket data.

Affected Products

  • Oxygenz ClipBucket v5, versions 5.5.2 - #151 and earlier
  • ClipBucket Custom Fields plugin (required to be installed and active)
  • Deployments exposing the administrative plugin interface to multiple admin accounts

Discovery Timeline

  • 2025-11-06 - CVE-2025-64114 published to the National Vulnerability Database
  • 2026-06-17 - Last updated in NVD database

Technical Details for CVE-2025-64114

Vulnerability Analysis

The vulnerability resides in the ClipBucket Custom Fields plugin shipped with ClipBucket v5. User-controlled parameters passed through the plugin's administrative endpoints are concatenated directly into SQL queries without parameterization or sufficient sanitization. An authenticated administrator with plugin management privileges can supply crafted input through the Custom Fields interface to alter query logic. Successful exploitation enables arbitrary SQL execution against the ClipBucket database, including read access to credential hashes, modification of user records, and manipulation of video metadata.

Root Cause

The root cause is improper neutralization of special characters passed to SQL statements built within the Custom Fields plugin logic. The upstream maintainers chose to remove the vulnerable component entirely rather than refactor its query construction. The patch migration M00152.php deletes the plugin registration from the plugins table and drops the custom_field table outright, eliminating the attack surface. The companion change in upload/admin_area/plugin.php adds an additional validation step that confirms a loaded plugin file is both registered and marked plugin_active = 'yes' before including it.

Attack Vector

Exploitation requires an authenticated session with administrative privileges and plugin management rights, and the Custom Fields plugin must be installed and reachable. The attack is delivered over the network against the admin area, with no user interaction required beyond the attacker's own session. Because the vulnerable code paths run with full database credentials, the impact extends to any table accessible to the ClipBucket database user.

php
// Patch: upload/cb_install/sql/5.5.2/M00152.php
// The maintainers remove the vulnerable Custom Fields plugin and its table
<?php

namespace V5_5_2;
require_once \DirPath::get('classes') . DIRECTORY_SEPARATOR . 'migration' . DIRECTORY_SEPARATOR . 'migration.class.php';

class M00152 extends \Migration
{
    /**
     * @throws \Exception
     */
    public function start()
    {
        $sql='DELETE FROM `{tbl_prefix}plugins` WHERE `plugin_file` = \'customfield.php\'';
        self::query($sql);

        $sql='DROP TABLE IF EXISTS `{tbl_prefix}custom_field`';
        self::query($sql);
    }

}

Source: GitHub Commit b7289923

Detection Methods for CVE-2025-64114

Indicators of Compromise

  • Presence of the custom_field table or an entry for customfield.php in the plugins table on ClipBucket versions at or above 5.5.2 - #152.
  • Web server access logs showing POST or GET requests to admin plugin endpoints referencing the Custom Fields plugin with SQL metacharacters such as single quotes, UNION, SLEEP(, or comment sequences.
  • Unexpected administrator-authored queries against sensitive tables, such as users or sessions, outside of normal application traffic patterns.

Detection Strategies

  • Review ClipBucket admin audit trails for Custom Fields plugin interactions by any account other than approved maintainers.
  • Enable MySQL or MariaDB general or slow query logging and search for suspicious query shapes originating from the ClipBucket database user.
  • Deploy web application firewall rules that inspect requests to /admin_area/plugin.php and related Custom Fields endpoints for SQL injection payloads.

Monitoring Recommendations

  • Alert on any schema modification, data export, or INFORMATION_SCHEMA enumeration performed by the ClipBucket database account.
  • Monitor administrative session creation and privilege changes within ClipBucket to identify misuse or compromise of plugin management rights.
  • Correlate authentication events with plugin configuration changes to surface anomalous administrator behavior.

How to Mitigate CVE-2025-64114

Immediate Actions Required

  • Upgrade ClipBucket v5 to release 5.5.2 - #152 or later, which removes the vulnerable Custom Fields plugin.
  • Audit all accounts with administrator and plugin management privileges and revoke access that is not strictly required.
  • Rotate ClipBucket administrator credentials and database passwords if exploitation is suspected.

Patch Information

The fix is delivered in GitHub Release v5.5.2 #152 and detailed in GitHub Security Advisory GHSA-4g7x-j562-8g69. The upstream commit b7289923 uninstalls the Custom Fields plugin, drops its database table, and adds an active-plugin check before including plugin files from the admin area.

Workarounds

  • If immediate patching is not possible, disable and remove the Custom Fields plugin from the ClipBucket admin interface.
  • Restrict access to the /admin_area/ path at the web server or reverse proxy layer to trusted IP ranges only.
  • Apply least-privilege permissions on the MySQL or MariaDB account used by ClipBucket to limit the impact of injected queries.
bash
# Example: restrict ClipBucket admin area to trusted sources in nginx
location /admin_area/ {
    allow 10.0.0.0/24;    # internal admin network
    deny  all;
    try_files $uri $uri/ /admin_area/index.php?$args;
}

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.