PT-2020-15962 · Vbulletin Solutions · Vbulletin
Published
2020-09-03
·
Updated
2020-09-04
·
CVE-2020-25122
CVSS v3.1
4.8
Medium
| Vector | AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
vBulletin version 5.6.3
Description
The issue concerns a Cross-Site Scripting (XSS) flaw in the Admin CP of the affected software. Specifically, the vulnerability can be triggered via a Rank Type in the User Rank Manager.
Recommendations
For version 5.6.3, consider disabling the User Rank Manager or restricting access to it until a fix is available. Avoid using the Rank Type feature in the User Rank Manager to minimize the risk of exploitation.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Vbulletin