PT-2020-13228 · Vbulletin Solutions · Vbulletin

Published

2020-05-07

·

Updated

2022-04-27

·

CVE-2020-12720

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions vBulletin versions 5.5.6 and earlier, 5.6.0 before 5.6.0pl1, 5.6.1 before 5.6.1pl1
Description The issue is related to incorrect access control in vBulletin.
Recommendations For versions 5.5.6 and earlier, update to version 5.5.6pl1 or later. For version 5.6.0, update to version 5.6.0pl1 or later. For version 5.6.1, update to version 5.6.1pl1 or later.

Exploit

Fix

SQL injection

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-12720

Affected Products

Vbulletin