vendor:
vBulletin
by:
Discovered by ROOT_EGY
7.5
CVSS
HIGH
XSS
79
CWE
Product Name: vBulletin
Affected Version From: 3.5.2002
Affected Version To: 3.5.2002
Patch Exists: NO
Related CWE:
CPE: a:vbulletin:vbulletin:3.5.2
Platforms Tested:
vBulletin Version 3.5.2 – Introduction XSS scripting
The vulnerability is in the field "title" scenario "calendar.php". An attacker can inject malicious JavaScript code into the title field of a calendar event, which will be executed when the event is viewed. This allows the attacker to steal the victim's cookies.
Mitigation:
Upgrade to a patched version of vBulletin.