Cross-Site Scripting Vulnerability in vBulletin 5.6.3
CVE-2020-25123
4.8MEDIUM
What is CVE-2020-25123?
In vBulletin version 5.6.3, a security flaw has been identified that allows attackers to inject malicious scripts through the Smilie Title in the Smilies Manager. This Cross-Site Scripting (XSS) vulnerability can compromise user sessions, manipulate web content, and potentially lead to the revealing of sensitive information. It’s critical for administrators and users to apply necessary updates to safeguard their systems against exploitation.