CVE-2016-6483: SSRF
The media-file upload feature in vBulletin before 3.8.7 Patch Level 6, 3.8.8 before Patch Level 2, 3.8.9 before Patch Level 1, 4.x before 4.2.2 Patch Level 6, 4.2.3 before Patch Level 2, 5.x before 5.2.0 Patch Level 3, 5.2.1 before Patch Level 1, and 5.2.2 before Patch Level 1 allows remote attackers to conduct SSRF attacks via a crafted URL that results in a Redirection HTTP status code.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2016-6483?
CVE-2016-6483 has a Medium severity rating due to its potential for remote code execution.
How do I fix CVE-2016-6483?
To fix CVE-2016-6483, upgrade your vBulletin installation to the latest patched version.
Which vBulletin versions are affected by CVE-2016-6483?
vBulletin versions prior to 3.8.7 Patch Level 6, 3.8.8 Patch Level 2, 3.8.9 Patch Level 1, 4.x before 4.2.2 Patch Level 6, 4.2.3 Patch Level 2, 5.x before 5.2.0 Patch Level 3, 5.2.1 Patch Level 1, and 5.2.2 Patch Level 1 are affected.
Can CVE-2016-6483 be exploited remotely?
Yes, CVE-2016-6483 allows remote attackers to exploit the vulnerability.
What is the impact of CVE-2016-6483?
The impact of CVE-2016-6483 can lead to unintended access to internal services or data due to the SSRF vulnerability.