CVE-2019-16759: vBulletin PHP Module Remote Code Execution Vulnerability
vBulletin 5.x through 5.5.4 allows remote command execution via the widgetConfig[code] parameter in an ajax/render/widgetphp routestring request.
Other sources
The PHP module within vBulletin contains an unspecified vulnerability that allows for remote code execution via the widgetConfig[code] parameter in an ajax/render/widgetphp routestring request.
— CISA
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-16759?
CVE-2019-16759 is a vulnerability in the vBulletin PHP module that allows for remote code execution.
How does CVE-2019-16759 work?
The vulnerability allows attackers to execute remote code by exploiting the widgetConfig[code] parameter in an ajax/render/widget_php routestring request.
Which software versions are affected by CVE-2019-16759?
vBulletin versions 5.0.0 to 5.5.4 are affected by CVE-2019-16759.
What is the severity of CVE-2019-16759?
CVE-2019-16759 has a severity rating of 9.8, which is considered critical.
How can CVE-2019-16759 be fixed?
To fix CVE-2019-16759, it is recommended to update vBulletin to a version that has addressed the vulnerability.