Junglewise Threat Intelligence

CVE-2020-17496: vBulletin PHP Module Remote Code Execution Vulnerability

CVE-2020-17496 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2021-11-03

Technologies: Vbulletin. Vendors: Vbulletin.

Executive brief

The PHP module in vBulletin allows for remote code execution due to improper neutralization of special elements in subWidgets data. An attacker can trigger this via a specially crafted ajax/render/widget_tabbedcontainer_tab_panel request, bypassing an incomplete patch for CVE-2019-16759.

Affected products

  • vBulletin vBulletin 5.5.4 through 5.6.2

Timeline

  • 2020-08-12: disclosed: NVD Published Date
  • 2021-11-03: kev added: Date added to CISA Known Exploited Vulnerabilities Catalog
  • exploited: Reported as exploited in the wild and included in CISA KEV catalog.
  • 2020-08-17: patched: NIST analysis notes vendor security patch availability.

Related threats