CVE-2020-25123: XSS
Published Sep 3, 2020
·Updated
The Admin CP in vBulletin 5.6.3 allows XSS via a Smilie Title to Smilies Manager.
Affected Software
1 affected component
vBulletin vBulletin=5.6.3
Event History
Sep 3, 2020
CVE Published
via MITRE·05:18 PM
Data Sourced
via MITRE·05:18 PM
Description
Frequently Asked Questions
1
What is CVE-2020-25123?
CVE-2020-25123 is a vulnerability in vBulletin 5.6.3 that allows XSS via a Smilie Title to Smilies Manager.
2
How severe is CVE-2020-25123?
CVE-2020-25123 is considered to have a medium severity with a CVSS score of 4.8.
3
What software versions are affected by CVE-2020-25123?
CVE-2020-25123 affects vBulletin version 5.6.3.
4
How can the XSS vulnerability in CVE-2020-25123 be exploited?
The XSS vulnerability in CVE-2020-25123 can be exploited by using a malicious Smilie Title in the Smilies Manager.
5
Is there a fix available for CVE-2020-25123?
At this time, there is no official fix available for CVE-2020-25123. It is recommended to update to a newer version of vBulletin when a patch becomes available.