CVE-2023-25135: Critical severity vbulletin vulnerability
vBulletin before 5.6.9 PL1 allows an unauthenticated remote attacker to execute arbitrary code via a crafted HTTP request that triggers deserialization. This occurs because verifyserialized checks that a value is serialized by calling unserialize and then checking for errors. The fixed versions are 5.6.7 PL1, 5.6.8 PL1, and 5.6.9 PL1.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this security issue in vBulletin?
The vulnerability ID for this security issue in vBulletin is CVE-2023-25135.
What is the impact of the vulnerability CVE-2023-25135 in vBulletin?
The impact of the vulnerability CVE-2023-25135 in vBulletin is that an unauthenticated remote attacker can execute arbitrary code.
How does the vulnerability CVE-2023-25135 in vBulletin occur?
The vulnerability CVE-2023-25135 in vBulletin occurs due to a crafted HTTP request that triggers deserialization.
Is authentication required for the exploitation of CVE-2023-25135 in vBulletin?
No, authentication is not required for the exploitation of CVE-2023-25135 in vBulletin.
How can I fix the vulnerability CVE-2023-25135 in vBulletin?
To fix the vulnerability CVE-2023-25135 in vBulletin, update to the fixed versions which are 5.6.9 PL1 or later.