First published: Tue Sep 19 2017(Updated: )
vBulletin 5.x through 5.1.6 allows remote authenticated users to bypass authorization checks and inject private messages into conversations via vectors related to an input validation failure.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
vBulletin vBulletin | =5.0.0-beta_11 | |
vBulletin vBulletin | =5.0.0-beta_28 | |
vBulletin vBulletin | =5.0.1 | |
vBulletin vBulletin | =5.0.2 | |
vBulletin vBulletin | =5.0.3 | |
vBulletin vBulletin | =5.0.4 | |
vBulletin vBulletin | =5.0.5 | |
vBulletin vBulletin | =5.1.0 | |
vBulletin vBulletin | =5.1.0-rc1 | |
vBulletin vBulletin | =5.1.1 | |
vBulletin vBulletin | =5.1.2-beta1 | |
vBulletin vBulletin | =5.1.2-rc1 | |
vBulletin vBulletin | =5.1.2-rc2 | |
vBulletin vBulletin | =5.1.3 | |
vBulletin vBulletin | =5.1.3-alpha5 | |
vBulletin vBulletin | =5.1.3-rc1 | |
vBulletin vBulletin | =5.1.4 | |
vBulletin vBulletin | =5.1.4-rc1 | |
vBulletin vBulletin | =5.1.5 | |
vBulletin vBulletin | =5.1.5-beta_1 | |
vBulletin vBulletin | =5.1.5-beta_3 | |
vBulletin vBulletin | =5.1.6 | |
vBulletin vBulletin | =5.1.6-beta_2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.