CRITICAL🚩 CISA KEV⚡ EXPLOIT✓ PATCH🇵🇱 Wersja polska

CVE-2020-17496

CVSS 9.8v3.1pub. 2020-08-12upd. 2025-11-07

vBulletin 5.5.4 through 5.6.2 allows remote command execution via crafted subWidgets data in an ajax/render/widget_tabbedcontainer_tab_panel request. NOTE: this issue exists because of an incomplete fix for CVE-2019-16759.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Vbulletin

    APP
    Vbulletin
    5.5.4 – 5.6.2

CISA KEV — detailsi

Vendori
vBulletin
Producti
vBulletin
Added to KEVi
November 3, 2021
Remediation deadline (US Federal)i
May 3, 2022(overdue)
Required action (CISA)i

Apply updates per vendor instructions.

CISA descriptioni

The PHP module within vBulletin contains an unspecified vulnerability that allows for remote code execution via crafted subWidgets data in an ajax/render/widget_tabbedcontainer_tab_panel request. This CVE ID resolves an incomplete patch for CVE-2019-16759.

🔴
IMMEDIATE ACTION
Actively exploited in the wild (CISA KEV). Patch immediately.
CISA DEADLINE: 3 maja 2022
Tags
Container
CWE
References

Related vulnerabilities

CVE-2019-16759CRITICAL9.8⚠ KEVPL ✓same product

RCE bez uwierzytelnienia w vBulletin 5.x przez parametr widgetConfig[code]

CVE-2025-48828CRITICAL9.0PL ✓same product

RCE w vBulletin poprzez Template Conditionals — wykonanie dowolnego kodu PHP

CVE-2025-48827CRITICAL10.0PL ✓same product

vBulletin — nieautoryzowany dostęp do chronionych metod API (RCE)

CVE-2023-25135CRITICAL9.8PL ✓same product

vBulletin RCE przez deserializację bez uwierzytelnienia (pre-5.6.9 PL1)

CVE-2020-7373CRITICAL9.8PL ✓same product

vBulletin 5.5.4–5.6.2: RCE przez niekompletną łatę CVE-2019-16759