vBulletin
cpe:2.3:a:vbulletin:vbulletin:*:*:*:*:*:*:*
- >= 5.5.4, <= 5.6.2
This vulnerability is being actively exploited in the wild.
A remote code execution vulnerability exists in vBulletin versions 5.5.4 prior to 5.6.2. This issue arises from an incomplete fix for a previous vulnerability (CVE-2019-16759) and allows execution of arbitrary PHP code through manipulated subWidgets data in an ajax/render/widget_tabbedcontainer_tab_panel request.
Exploitation of this vulnerability allows authenticated users to execute arbitrary PHP code on the server, potentially leading to full compromise of the web application or server.
To reproduce this vulnerability, send a POST request to the '/ajax/render/widget_tabbedcontainer_tab_panel' endpoint. Include 'subWidgets[0][template]' set to 'widget_php' and 'subWidgets[0][config][code]' containing the PHP code to execute. The server will process the request and execute the injected PHP code, returning the output.
Users can update to vBulletin versions 5.6.3 or later, where this vulnerability has been patched.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.