CVE-2017-7569: SSRF
In vBulletin before 5.3.0, remote attackers can bypass the CVE-2016-6483 patch and conduct SSRF attacks by leveraging the behavior of the PHP parseurl function, aka VBV-17037.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
vBulletinto a version that resolves this vulnerability.Fixed in 5.3.0Patch VBV-17037
Event History
Frequently Asked Questions
What is the severity of CVE-2017-7569?
CVE-2017-7569 is considered a critical vulnerability due to its potential to allow remote attackers to perform SSRF attacks.
How do I fix CVE-2017-7569?
To fix CVE-2017-7569, upgrade vBulletin to version 5.3.0 or later.
What kind of attacks does CVE-2017-7569 allow?
CVE-2017-7569 allows remote attackers to bypass a previous security patch and conduct Server-Side Request Forgery (SSRF) attacks.
Which vBulletin versions are affected by CVE-2017-7569?
CVE-2017-7569 affects all vBulletin versions prior to 5.3.0.
What is the patch associated with CVE-2017-7569?
The patch associated with CVE-2017-7569 is included in vBulletin version 5.3.0, which addresses the SSRF vulnerability.