CVE-2015-3419: Input Validation
Published Sep 19, 2017
·Updated
vBulletin 5.x through 5.1.6 allows remote authenticated users to bypass authorization checks and inject private messages into conversations via vectors related to an input validation failure.
Affected Software
23 affected components
vBulletin vBulletin=5.0.0-beta_11
vBulletin vBulletin=5.0.0-beta_28
vBulletin vBulletin=5.0.1
vBulletin vBulletin=5.0.2
vBulletin vBulletin=5.0.3
vBulletin vBulletin=5.0.4
vBulletin vBulletin=5.0.5
vBulletin vBulletin=5.1.0
vBulletin vBulletin=5.1.0-rc1
vBulletin vBulletin=5.1.1
vBulletin vBulletin=5.1.2-beta1
vBulletin vBulletin=5.1.2-rc1
vBulletin vBulletin=5.1.2-rc2
vBulletin vBulletin=5.1.3
vBulletin vBulletin=5.1.3-alpha5
vBulletin vBulletin=5.1.3-rc1
vBulletin vBulletin=5.1.4
vBulletin vBulletin=5.1.4-rc1
vBulletin vBulletin=5.1.5
vBulletin vBulletin=5.1.5-beta_1
vBulletin vBulletin=5.1.5-beta_3
vBulletin vBulletin=5.1.6
vBulletin vBulletin=5.1.6-beta_2
Event History
Sep 19, 2017
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-3419?
The severity of CVE-2015-3419 is rated as high due to its potential for authorization bypass and message injection.
2
How do I fix CVE-2015-3419?
To fix CVE-2015-3419, upgrade your vBulletin installation to version 5.1.6 or later.
3
Which versions of vBulletin are affected by CVE-2015-3419?
Affected versions include vBulletin 5.x up to 5.1.6, specifically versions 5.0.0 through 5.1.6.
4
What type of vulnerability is CVE-2015-3419?
CVE-2015-3419 is an authorization bypass vulnerability that allows remote authenticated users to exploit input validation failures.
5
Can CVE-2015-3419 be exploited remotely?
Yes, CVE-2015-3419 can be exploited remotely by authenticated users.