Junglewise Threat Intelligence

CVE-2019-16759: vBulletin PHP Module Remote Code Execution Vulnerability

CVE-2019-16759 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2021-11-03

Technologies: Vbulletin. Vendors: Vbulletin.

Executive brief

vBulletin 5.x through 5.5.4 contains a remote code execution vulnerability in its PHP module. An attacker can execute arbitrary commands by sending a specially crafted request to the ajax/render/widget_php routestring using the widgetConfig[code] parameter.

Affected products

  • vBulletin vBulletin 5.x through 5.5.4

Timeline

  • 2019-09-23: disclosed: Public exploit code released as a 0-day
  • 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog

Related threats