vendor:
vBulletin
by:
@zenofex
9.8
CVSS
CRITICAL
Remote Code Execution
94
CWE
Product Name: vBulletin
Affected Version From: 5.4.5
Affected Version To: 5.6.2
Patch Exists: YES
Related CWE: CVE-2019-16759
CPE: a:vbulletin:vbulletin:5.6.2
Other Scripts:
N/A
Platforms Tested: Ubuntu 19.04
2020
vBulletin 5.6.2 – ‘widget_tabbedContainer_tab_panel’ Remote Code Execution
vBulletin 5.5.4 through 5.6.2 are vulnerable to a remote code execution vulnerability caused by incomplete patching of the previous 'CVE-2019-16759' RCE. This logic bug allows for a single pre-auth request to execute PHP code on a target vBulletin forum.
Mitigation:
Apply the latest security patches and updates to the vBulletin software.