First published: Thu Sep 03 2020(Updated: )
The Admin CP in vBulletin 5.6.3 allows XSS via an Occupation Title or Description to User Profile Field Manager.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
vBulletin vBulletin | =5.6.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-25115 is a vulnerability in vBulletin 5.6.3 that allows for cross-site scripting (XSS) attacks via an Occupation Title or Description to User Profile Field Manager.
CVE-2020-25115 has a severity score of 4.8 out of 10, which is considered medium severity.
CVE-2020-25115 affects vBulletin 5.6.3.
CVE-2020-25115 is classified under CWE-79, which is the category for Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting').
Yes, a fix is available for CVE-2020-25115. It is recommended to update to the latest version of vBulletin to address this vulnerability.