CVE-2020-25117: XSS
Published Sep 3, 2020
·Updated
The Admin CP in vBulletin 5.6.3 allows XSS via a Junior Member Title to User Title Manager.
Affected Software
1 affected component
vBulletin vBulletin=5.6.3
Event History
Sep 3, 2020
CVE Published
via MITRE·05:20 PM
Data Sourced
via MITRE·05:20 PM
Description
Frequently Asked Questions
1
What is CVE-2020-25117?
CVE-2020-25117 is a vulnerability in the Admin CP of vBulletin 5.6.3 that allows XSS (Cross-Site Scripting) attacks via a Junior Member Title to User Title Manager.
2
How severe is CVE-2020-25117?
CVE-2020-25117 has a severity rating of 4.8 out of 10 (medium severity).
3
How does CVE-2020-25117 affect vBulletin?
CVE-2020-25117 affects vBulletin version 5.6.3.
4
What is the Common Vulnerabilities and Exposures (CVE) ID for this vulnerability?
The Common Vulnerabilities and Exposures (CVE) ID for this vulnerability is CVE-2020-25117.
5
How can I fix CVE-2020-25117?
To fix CVE-2020-25117, it is recommended to upgrade to a patched version of vBulletin that addresses the XSS vulnerability.