SSRF Vulnerability in vBulletin by vBulletin Solutions
CVE-2016-6483

8.6HIGH

Key Information:

Vendor

Vbulletin

Status
Vendor
CVE Published:
2 September 2016

What is CVE-2016-6483?

The media-file upload feature in various versions of vBulletin allows remote attackers to exploit a Server-Side Request Forgery (SSRF) vulnerability. By crafting a malicious URL, attackers can submit requests to internal resources that may expose sensitive information or facilitate further attacks due to the vulnerability's redirection capabilities. This issue primarily affects numerous vBulletin versions before specific patch levels, making it critical to apply the recommended updates to mitigate potential risks.

References

EPSS Score

22% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
8.6
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2016-6483 : SSRF Vulnerability in vBulletin by vBulletin Solutions