First published: Thu Sep 03 2020(Updated: )
The Admin CP in vBulletin 5.6.3 allows XSS via a Style Options Settings Title to Styles Manager.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
vBulletin vBulletin | =5.6.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-25118 is a vulnerability in vBulletin 5.6.3 that allows XSS (Cross-Site Scripting) attacks via a Style Options Settings Title to Styles Manager.
The severity of CVE-2020-25118 is classified as medium with a severity value of 4.8.
vBulletin 5.6.3 is a specific version of the vBulletin software.
CVE-2020-25118 allows attackers to execute malicious scripts on vBulletin 5.6.3 by exploiting the Style Options Settings Title to Styles Manager functionality.
To mitigate the vulnerability in vBulletin 5.6.3, it is recommended to update to a patched version of the software provided by vBulletin.