CVE-2020-25122: XSS
Published Sep 3, 2020
·Updated
The Admin CP in vBulletin 5.6.3 allows XSS via a Rank Type to User Rank Manager.
Affected Software
1 affected component
vBulletin vBulletin=5.6.3
Event History
Sep 3, 2020
CVE Published
via MITRE·05:19 PM
Data Sourced
via MITRE·05:19 PM
Description
Frequently Asked Questions
1
What is CVE-2020-25122?
CVE-2020-25122 is a vulnerability that allows XSS (cross-site scripting) attacks in the Admin CP of vBulletin 5.6.3.
2
How severe is CVE-2020-25122?
CVE-2020-25122 has a severity rating of 4.8, which is considered medium.
3
How does CVE-2020-25122 occur?
CVE-2020-25122 occurs when an attacker injects malicious code into the Rank Type field of the User Rank Manager in vBulletin 5.6.3's Admin CP, leading to XSS attacks.
4
What is the affected software version for CVE-2020-25122?
The affected software version for CVE-2020-25122 is vBulletin 5.6.3.
5
How can I mitigate the vulnerability in CVE-2020-25122?
To mitigate the vulnerability in CVE-2020-25122, it is recommended to upgrade vBulletin to a newer version that includes a fix for this issue.