CVE-2020-25119: XSS
The Admin CP in vBulletin 5.6.3 allows XSS via a Title of a Child Help Item in the Login/Logoff part of the User Manual.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-25119?
CVE-2020-25119 is a vulnerability in vBulletin 5.6.3 that allows cross-site scripting (XSS) attacks via the title of a child help item in the Login/Logoff section of the User Manual.
How severe is CVE-2020-25119?
CVE-2020-25119 has a severity rating of 4.8, which is considered medium.
How does CVE-2020-25119 affect vBulletin?
CVE-2020-25119 affects vBulletin 5.6.3, specifically the Admin Control Panel (CP) and the Login/Logoff part of the User Manual.
How can the XSS vulnerability in CVE-2020-25119 be exploited?
The XSS vulnerability in CVE-2020-25119 can be exploited by injecting malicious code into the title of a child help item in the Login/Logoff section of the User Manual.
Is there a fix for CVE-2020-25119?
Yes, to fix CVE-2020-25119, update vBulletin to a version that is not affected by this vulnerability.