PT-2020-15956 · Vbulletin Solutions · Vbulletin
Published
2020-09-03
·
Updated
2020-09-04
·
CVE-2020-25116
CVSS v3.1
4.8
Medium
| Vector | AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
vBulletin version 5.6.3
Description
The issue concerns an XSS vulnerability in the Admin CP of vBulletin, specifically via an Announcement Title to Channel Manager.
Recommendations
For version 5.6.3, consider disabling the Announcement Title feature in the Channel Manager until a patch is available to prevent potential XSS exploitation.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Vbulletin