QID 731098
QID 731098: vBulletin Remote Code Execution Vulnerability (CVE-2023-25135)
vBulletin is commercial Web forum software written in PHP and back-ended by a MySQL database. It runs on most Linux and Unix variants, as well as Microsoft Windows.
vBulletin before 5.6.9 PL1 allows an unauthenticated remote attacker to execute arbitrary code via a crafted HTTP request that triggers deserialization.
Affected Versions:
Vbulletin all versions upto 5.6.9
QID Detection Logic:
This QID sends a crafted HTTP GET request to check if the target is vulnerable or not.
Successful exploitation of this vulnerability may allow attackers to execute arbitrary code, gain unauthorized access, and compromise data integrity on vBulletin instances before version 5.6.9 PL1.
Solution
Customers are advised to upgrade to the latest versions vbulletin or later versions to remediate this vulnerability.
Vendor References
CVEs related to QID 731098
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| vBulletin |
|