PT-2020-13228 · Vbulletin Solutions · Vbulletin
Published
2020-05-07
·
Updated
2022-04-27
·
CVE-2020-12720
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
vBulletin versions 5.5.6 and earlier, 5.6.0 before 5.6.0pl1, 5.6.1 before 5.6.1pl1
Description
The issue is related to incorrect access control in vBulletin.
Recommendations
For versions 5.5.6 and earlier, update to version 5.5.6pl1 or later.
For version 5.6.0, update to version 5.6.0pl1 or later.
For version 5.6.1, update to version 5.6.1pl1 or later.
Exploit
Fix
SQL injection
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Vbulletin