vendor:
vBSSO Single Sign-On
by:
Technidev
7.5
CVSS
HIGH
SQL Injection
89
CWE
Product Name: vBSSO Single Sign-On
Affected Version From: <= 1.4.14
Affected Version To: >= 1.4.15
Patch Exists: YES
Related CWE: N/A
CPE: vbulletin:vbssosignon
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2015
vBulletin vBSSO Single Sign-On – <= 1.4.14 – SQL Injection
This plugin is vulnerable to SQL injection at the /vbsso/avatar.php file in the fetchUserinfo function. It requires a big UNION ALL SELECT query and commenting out the LIMIT function of SQL. If SQL injection is a success, the browser will redirect the user to a URL where the URL contains the extracted information.
Mitigation:
Upgrade to version 1.4.15 or later.