First published: Thu Sep 03 2020(Updated: )
The Admin CP in vBulletin 5.6.3 allows XSS via a Title of a Child Help Item in the Login/Logoff part of the User Manual.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
vBulletin vBulletin | =5.6.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-25119 is a vulnerability in vBulletin 5.6.3 that allows cross-site scripting (XSS) attacks via the title of a child help item in the Login/Logoff section of the User Manual.
CVE-2020-25119 has a severity rating of 4.8, which is considered medium.
CVE-2020-25119 affects vBulletin 5.6.3, specifically the Admin Control Panel (CP) and the Login/Logoff part of the User Manual.
The XSS vulnerability in CVE-2020-25119 can be exploited by injecting malicious code into the title of a child help item in the Login/Logoff section of the User Manual.
Yes, to fix CVE-2020-25119, update vBulletin to a version that is not affected by this vulnerability.