Executive brief
The PHP module in vBulletin allows for remote code execution due to improper neutralization of special elements in subWidgets data. An attacker can trigger this via a specially crafted ajax/render/widget_tabbedcontainer_tab_panel request, bypassing an incomplete patch for CVE-2019-16759.
Affected products
- vBulletin vBulletin 5.5.4 through 5.6.2
Timeline
- 2020-08-12: disclosed: NVD Published Date
- 2021-11-03: kev added: Date added to CISA Known Exploited Vulnerabilities Catalog
- exploited: Reported as exploited in the wild and included in CISA KEV catalog.
- 2020-08-17: patched: NIST analysis notes vendor security patch availability.