CVE-2019-17271: SQL Injection
vBulletin 5.5.4 allows SQL Injection via the ajax/api/hook/getHookList or ajax/api/widget/getWidgetList where parameter.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2019-17271?
CVE-2019-17271 is a vulnerability in vBulletin 5.5.4 that allows SQL Injection via the ajax/api/hook/getHookList or ajax/api/widget/getWidgetList where parameter.
How severe is CVE-2019-17271?
CVE-2019-17271 has a severity rating of medium with a CVSS score of 4.9.
Which software versions are affected by CVE-2019-17271?
CVE-2019-17271 affects vBulletin versions up to and including 5.5.4.
How can I fix CVE-2019-17271?
To fix CVE-2019-17271, you should update vBulletin to a version that is not affected by the vulnerability.
Where can I find more information about CVE-2019-17271?
You can find more information about CVE-2019-17271 on the following websites: [Packet Storm Security](http://packetstormsecurity.com/files/154758/vBulletin-5.5.4-SQL-Injection.html), [vBulletin Forums](https://forum.vbulletin.com/forum/vbulletin-announcements/vbulletin-announcements_aa).