PT-2020-15962 · Vbulletin Solutions · Vbulletin

Published

2020-09-03

·

Updated

2020-09-04

·

CVE-2020-25122

CVSS v3.1

4.8

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions vBulletin version 5.6.3
Description The issue concerns a Cross-Site Scripting (XSS) flaw in the Admin CP of the affected software. Specifically, the vulnerability can be triggered via a Rank Type in the User Rank Manager.
Recommendations For version 5.6.3, consider disabling the User Rank Manager or restricting access to it until a fix is available. Avoid using the Rank Type feature in the User Rank Manager to minimize the risk of exploitation.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-25122

Affected Products

Vbulletin