PT-2018-11266 · Vbulletin+1 · Vbulletin 4+2

L4Rm4Nd

+1

·

Publicado

2018-06-19

·

Atualizado

2018-08-11

·

CVE-2018-12580

CVSS v3.1

6.1

Média

VetorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions DragonByte vBSecurity versions 3.x through 3.3.0 for vBulletin 3 and vBulletin 4
Description The issue allows self-XSS via the user agent variable in the "Login Sessions" feature. This occurs in the library/DBTech/Security/Action/Sessions.php file.
Recommendations For DragonByte vBSecurity versions 3.x through 3.3.0, consider restricting access to the "Login Sessions" feature until a fix is available. As a temporary workaround, avoid using the user agent variable in the affected feature to minimize the risk of exploitation.

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-12580

Produtos afetados

Dragonbyte Vbsecurity
Vbulletin 3
Vbulletin 4