Vbulletin Solutions · Vbulletin · CVE-2016-6195
**Name of the Vulnerable Software and Affected Versions**
vBulletin versions prior to 4.2.2 Patch Level 5
vBulletin versions 4.2.3 prior to Patch Level 1
**Description**
A SQL injection issue allows remote attackers to execute arbitrary SQL commands via the `postids` parameter to "forumrunner/request.php". This issue has been exploited in the wild.
**Recommendations**
For versions prior to 4.2.2 Patch Level 5, update to version 4.2.2 Patch Level 5 or later.
For versions 4.2.3 prior to Patch Level 1, update to version 4.2.3 Patch Level 1 or later.
As a temporary workaround, consider restricting access to the "forumrunner/request.php" endpoint to minimize the risk of exploitation.
Avoid using the `postids` parameter in the affected API endpoint until the issue is resolved.