Executive brief
vBulletin 5.x through 5.5.4 contains a remote code execution vulnerability in its PHP module. An attacker can execute arbitrary commands by sending a specially crafted request to the ajax/render/widget_php routestring using the widgetConfig[code] parameter.
Affected products
- vBulletin vBulletin 5.x through 5.5.4
Timeline
- 2019-09-23: disclosed: Public exploit code released as a 0-day
- 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog