vendor:
vBulletin
by:
MaXe (@InterN0T)
7,5
CVSS
HIGH
Persistent Cross Site Scripting
79
CWE
Product Name: vBulletin
Affected Version From: 4.0.8
Affected Version To: 4.0.8
Patch Exists: NO
Related CWE: N/A
CPE: vbulletin:vbulletin
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: IE6
2010
vBulletin 4.0.8 – Persistent XSS via Profile Customization
vBulletin is prone to a Persistent Cross Site Scripting vulnerability within the Profile Customization feature. If this feature is not enabled the vulnerability does not exist and the installation of vBulletin is thereby secure. Within the profile customization fields, it is possible to enter colour codes, rgb codes and even images. The image url() function does not sanitize user input in a sufficient way causing vBulletin to be vulnerable to XSS attacks.
Mitigation:
Turn off profile customization immediately for users able to customize their profile.