XSS Vulnerability in vBulletin 5.6.3 – Admin Control Panel
CVE-2020-25117

4.8MEDIUM

Key Information:

Vendor

Vbulletin

Status
Vendor
CVE Published:
3 September 2020

What is CVE-2020-25117?

The Admin Control Panel in vBulletin version 5.6.3 has a vulnerability that allows attackers to exploit Cross-Site Scripting (XSS) through the Junior Member Title to User Title Manager feature. This vulnerability permits unauthorized scripts to be executed in the browser of an administrator, potentially leading to compromised account integrity and data security.

References

CVSS V3.1

Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.