CVE-2020-25124: XSS
Published Sep 3, 2020
·Updated
The Admin CP in vBulletin 5.6.3 allows XSS via an admincp/attachment.php&do=rebuild&type= URI.
Affected Software
1 affected component
vBulletin vBulletin=5.6.3
Event History
Sep 3, 2020
CVE Published
via MITRE·05:18 PM
Data Sourced
via MITRE·05:18 PM
Description
Frequently Asked Questions
1
What is CVE-2020-25124?
CVE-2020-25124 is a vulnerability in vBulletin 5.6.3 that allows XSS (Cross-Site Scripting) attacks through a specific URI.
2
How severe is CVE-2020-25124?
CVE-2020-25124 has a severity keyword of 'medium' and a severity value of 4.8 out of 10.
3
How does CVE-2020-25124 affect vBulletin?
CVE-2020-25124 affects vBulletin version 5.6.3.
4
What is the CWE ID for CVE-2020-25124?
The CWE ID for CVE-2020-25124 is 79, which corresponds to Cross-Site Scripting (XSS) vulnerabilities.
5
Is there a fix available for CVE-2020-25124?
At the time of this writing, there is no official fix available for CVE-2020-25124. It is recommended to apply any patches or updates provided by vBulletin when they become available.