CVE-2020-25116: XSS
Published Sep 3, 2020
·Updated
The Admin CP in vBulletin 5.6.3 allows XSS via an Announcement Title to Channel Manager.
Affected Software
1 affected component
vBulletin vBulletin=5.6.3
Event History
Sep 3, 2020
CVE Published
via MITRE·05:20 PM
Data Sourced
via MITRE·05:20 PM
Description
Frequently Asked Questions
1
What is CVE-2020-25116?
CVE-2020-25116 is a vulnerability in the Admin CP of vBulletin 5.6.3 that allows XSS (Cross-Site Scripting) attacks via an Announcement Title to Channel Manager.
2
What is the severity of CVE-2020-25116?
CVE-2020-25116 has a severity keyword of 'medium' and a severity value of 4.8.
3
How does CVE-2020-25116 affect vBulletin?
CVE-2020-25116 affects vBulletin version 5.6.3.
4
How can an XSS attack be performed through CVE-2020-25116?
An attacker can perform an XSS attack through CVE-2020-25116 by exploiting the vulnerability in the Announcement Title to Channel Manager in the Admin CP of vBulletin 5.6.3.
5
Is there a fix available for CVE-2020-25116?
Yes, it is recommended to update vBulletin to a version that includes a fix for CVE-2020-25116.