CVE-2020-25118: XSS
Published Sep 3, 2020
·Updated
The Admin CP in vBulletin 5.6.3 allows XSS via a Style Options Settings Title to Styles Manager.
Affected Software
1 affected component
vBulletin vBulletin=5.6.3
Event History
Sep 3, 2020
CVE Published
via MITRE·05:19 PM
Data Sourced
via MITRE·05:19 PM
Description
Frequently Asked Questions
1
What is CVE-2020-25118?
CVE-2020-25118 is a vulnerability in vBulletin 5.6.3 that allows XSS (Cross-Site Scripting) attacks via a Style Options Settings Title to Styles Manager.
2
How severe is CVE-2020-25118?
The severity of CVE-2020-25118 is classified as medium with a severity value of 4.8.
3
What is vBulletin 5.6.3?
vBulletin 5.6.3 is a specific version of the vBulletin software.
4
How does CVE-2020-25118 impact vBulletin?
CVE-2020-25118 allows attackers to execute malicious scripts on vBulletin 5.6.3 by exploiting the Style Options Settings Title to Styles Manager functionality.
5
How can I mitigate the vulnerability in vBulletin 5.6.3?
To mitigate the vulnerability in vBulletin 5.6.3, it is recommended to update to a patched version of the software provided by vBulletin.