CVE-2020-17496: vBulletin PHP Module Remote Code Execution Vulnerability
vBulletin 5.5.4 through 5.6.2 allows remote command execution via crafted subWidgets data in an ajax/render/widgettabbedcontainertabpanel request. NOTE: this issue exists because of an incomplete fix for CVE-2019-16759.
Other sources
The PHP module within vBulletin contains an unspecified vulnerability that allows for remote code execution via crafted subWidgets data in an ajax/render/widgettabbedcontainertabpanel request. This CVE ID resolves an incomplete patch for CVE-2019-16759.
— CISA
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2020-17496?
CVE-2020-17496 is a vulnerability in the vBulletin PHP module that allows for remote code execution.
What is the severity of CVE-2020-17496?
CVE-2020-17496 has a severity rating of 9.8, which is considered critical.
What software is affected by CVE-2020-17496?
vBulletin versions 5.5.4 to 5.6.2 are affected by CVE-2020-17496.
How can CVE-2020-17496 be exploited?
CVE-2020-17496 can be exploited by sending crafted subWidgets data in an ajax/render/widget_tabbedcontainer_tab_panel request.
Is there a patch available for CVE-2020-17496?
Yes, a patch is available for CVE-2020-17496. Please refer to the official vBulletin announcements for the patch.