CVE-2023-39777: XSS
A cross-site scripting (XSS) vulnerability in the Admin Control Panel of vBulletin 5.7.5 and 6.0.0 allows attackers to execute arbitrary web scripts or HTML via the /login.php?do=login url parameter.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-39777?
CVE-2023-39777 is a cross-site scripting (XSS) vulnerability in the Admin Control Panel of vBulletin 5.7.5 and 6.0.0.
How does CVE-2023-39777 affect vBulletin?
CVE-2023-39777 allows attackers to execute arbitrary web scripts or HTML through the /login.php?do=login URL parameter in the Admin Control Panel of vBulletin 5.7.5 and 6.0.0.
What is the severity of CVE-2023-39777?
CVE-2023-39777 has a severity rating of medium, with a CVSS score of 5.4.
How can I fix CVE-2023-39777?
To fix CVE-2023-39777, it is recommended to update vBulletin to version 6.0.1 or later, as this vulnerability is fixed in newer versions.
Where can I find more information about CVE-2023-39777?
For more information about CVE-2023-39777, you can refer to the following link: [https://gist.github.com/GiongfNef/8fe658dce4c7fcf3a7b4e6387e50141c](https://gist.github.com/GiongfNef/8fe658dce4c7fcf3a7b4e6387e50141c)