Cross-Site Scripting Vulnerability in vBulletin by Internet Brands
CVE-2020-25122
4.8MEDIUM
What is CVE-2020-25122?
The Admin Control Panel (CP) of vBulletin version 5.6.3 is susceptible to a Cross-Site Scripting (XSS) attack. An attacker can exploit this vulnerability via the Rank Type feature, targeting the User Rank Manager. If successfully exploited, this flaw could allow unauthorized scripts to run in the context of an administrator's session, potentially compromising sensitive information and administrative functions.