Cross-Site Scripting Vulnerability in vBulletin Admin Control Panel
CVE-2023-39777

5.4MEDIUM

Key Information:

Vendor

Vbulletin

Status
Vendor
CVE Published:
16 September 2023

What is CVE-2023-39777?

A cross-site scripting vulnerability exists in the Admin Control Panel of vBulletin versions 5.7.5 and 6.0.0. This flaw allows attackers to inject and execute arbitrary web scripts or HTML through manipulated requests to the /login.php?do=login URL. Successful exploitation of this vulnerability can lead to unauthorized actions and data exposure, making it crucial for administrators to apply available patches and secure their systems.

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.