CVE-2019-17132: Input Validation
vBulletin through 5.5.4 mishandles custom avatars.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-17132?
CVE-2019-17132 is a vulnerability in vBulletin versions up to and including 5.5.4 that mishandles custom avatars.
How severe is CVE-2019-17132?
CVE-2019-17132 has a severity rating of 9.8 (critical).
How does CVE-2019-17132 affect vBulletin?
CVE-2019-17132 affects vBulletin versions up to and including 5.5.4.
How can I fix CVE-2019-17132?
To fix CVE-2019-17132, apply the security patch provided by vBulletin.
Where can I find more information about CVE-2019-17132?
You can find more information about CVE-2019-17132 at the following references: [http://packetstormsecurity.com/files/154759/vBulletin-5.5.4-Remote-Code-Execution.html](http://packetstormsecurity.com/files/154759/vBulletin-5.5.4-Remote-Code-Execution.html), [http://seclists.org/fulldisclosure/2019/Oct/9](http://seclists.org/fulldisclosure/2019/Oct/9), [https://forum.vbulletin.com/forum/vbulletin-announcements/vbulletin-announcements_aa/4423646-vbulletin-5-5-x-5-5-2-5-5-3-and-5-5-4-security-patch-level-2](https://forum.vbulletin.com/forum/vbulletin-announcements/vbulletin-announcements_aa/4423646-vbulletin-5-5-x-5-5-2-5-5-3-and-5-5-4-security-patch-level-2).