First published: Fri Oct 04 2019(Updated: )
vBulletin through 5.5.4 mishandles custom avatars.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
vBulletin vBulletin | <=5.5.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-17132 is a vulnerability in vBulletin versions up to and including 5.5.4 that mishandles custom avatars.
CVE-2019-17132 has a severity rating of 9.8 (critical).
CVE-2019-17132 affects vBulletin versions up to and including 5.5.4.
To fix CVE-2019-17132, apply the security patch provided by vBulletin.
You can find more information about CVE-2019-17132 at the following references: [http://packetstormsecurity.com/files/154759/vBulletin-5.5.4-Remote-Code-Execution.html](http://packetstormsecurity.com/files/154759/vBulletin-5.5.4-Remote-Code-Execution.html), [http://seclists.org/fulldisclosure/2019/Oct/9](http://seclists.org/fulldisclosure/2019/Oct/9), [https://forum.vbulletin.com/forum/vbulletin-announcements/vbulletin-announcements_aa/4423646-vbulletin-5-5-x-5-5-2-5-5-3-and-5-5-4-security-patch-level-2](https://forum.vbulletin.com/forum/vbulletin-announcements/vbulletin-announcements_aa/4423646-vbulletin-5-5-x-5-5-2-5-5-3-and-5-5-4-security-patch-level-2).