vBulletin 5.5.4 through 5.6.2 allows remote command execution via crafted subWidgets data in an ajax/render/widget_tabbedcontainer_tab_panel request. NOTE: this issue exists because of an incomplete fix for CVE-2019-16759.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HVbulletin
APPVbulletin5.5.4 – 5.6.2
CISA KEV — detailsi
- Vendori
- vBulletin
- Producti
- vBulletin
- Added to KEVi
- November 3, 2021
- Remediation deadline (US Federal)i
- May 3, 2022(overdue)
Apply updates per vendor instructions.
The PHP module within vBulletin contains an unspecified vulnerability that allows for remote code execution via crafted subWidgets data in an ajax/render/widget_tabbedcontainer_tab_panel request. This CVE ID resolves an incomplete patch for CVE-2019-16759.
Related vulnerabilities
RCE bez uwierzytelnienia w vBulletin 5.x przez parametr widgetConfig[code]
RCE w vBulletin poprzez Template Conditionals — wykonanie dowolnego kodu PHP
vBulletin — nieautoryzowany dostęp do chronionych metod API (RCE)
vBulletin RCE przez deserializację bez uwierzytelnienia (pre-5.6.9 PL1)
vBulletin 5.5.4–5.6.2: RCE przez niekompletną łatę CVE-2019-16759