CVE-2020-17496
קריטית 9.8 מנוצלת בשטח (KEV)
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- vBulletin PHP Module Remote Code Execution Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply updates per vendor instructions.
תיאור (מקור, אנגלית)
vBulletin 5.5.4 through 5.6.2 allows remote command execution via crafted subWidgets data in an ajax/render/widget_tabbedcontainer_tab_panel request. NOTE: this issue exists because of an incomplete fix for CVE-2019-16759.
מדדים
- CVSS 3.1
-
9.8 (CRITICAL)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - EPSS — סבירות ניצול
- 88% (אחוזון 100) נכון ל-24/7/2026
- CWE
- CWE-74
מוצרים מושפעים
vbulletin: vbulletin
קישורים
- https://forum.vbulletin.com/forum/vbulletin-announcements/vbulletin-announceme… PatchVendor Advisory
- https://forum.vbulletin.com/forum/vbulletin-announcements/vbulletin-announceme… PatchVendor Advisory
- https://blog.exploitee.rs/2020/exploiting-vbulletin-a-tale-of-patch-fail/ ExploitThird Party Advisory
- https://seclists.org/fulldisclosure/2020/Aug/5 ExploitMailing ListThird Party Advisory
- https://blog.exploitee.rs/2020/exploiting-vbulletin-a-tale-of-patch-fail/ ExploitThird Party Advisory
- https://seclists.org/fulldisclosure/2020/Aug/5 ExploitMailing ListThird Party Advisory
- https://cwe.mitre.org/data/definitions/78.html Technical Description
- https://cwe.mitre.org/data/definitions/78.html Technical Description
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-202… US Government Resource