CVE-2020-25115: XSS
Published Sep 3, 2020
·Updated
The Admin CP in vBulletin 5.6.3 allows XSS via an Occupation Title or Description to User Profile Field Manager.
Affected Software
1 affected component
vBulletin vBulletin=5.6.3
Event History
Sep 3, 2020
CVE Published
via MITRE·05:20 PM
Data Sourced
via MITRE·05:20 PM
Description
Frequently Asked Questions
1
What is CVE-2020-25115?
CVE-2020-25115 is a vulnerability in vBulletin 5.6.3 that allows for cross-site scripting (XSS) attacks via an Occupation Title or Description to User Profile Field Manager.
2
How severe is CVE-2020-25115?
CVE-2020-25115 has a severity score of 4.8 out of 10, which is considered medium severity.
3
How does CVE-2020-25115 affect vBulletin?
CVE-2020-25115 affects vBulletin 5.6.3.
4
What is the Common Weakness Enumeration (CWE) ID for CVE-2020-25115?
CVE-2020-25115 is classified under CWE-79, which is the category for Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting').
5
Is there a fix available for CVE-2020-25115?
Yes, a fix is available for CVE-2020-25115. It is recommended to update to the latest version of vBulletin to address this vulnerability.