oday RCE in vBulletin v5.0.0-v5.5.4 fix bypass

By
Anandhu Krishnan
Published on
01 Oct 2021
Vulnerability

The widgetConfig[code] option in an ajax/render/widget php routestring request in vBulletin 5.x to 5.5.4 permits remote command execution

Mitigation / Precaution

We suggest you update vBulletin before 5.5.2 to a fixed version as soon as possible.


Written by
Anandhu Krishnan
Anandhu Krishnan
Lead Engineer
Experience the Beagle Security platform
Unlock one full penetration test and all Advanced plan features free for 10 days