EXPOSURES › CVE-2019-16759
CVE-2019-16759
HIGH ⌖ ON CISA KEV · EXPLOITEDvBulletin's PHP module allowed remote code execution via an unvalidated widget configuration parameter, enabling attackers to inject arbitrary code into forum instances.
The vulnerability in vBulletin's PHP module allowed remote code execution through the widgetConfig[code] parameter, letting attackers inject malicious code into forum pages. DIB organizations must ensure their forum software is patched and monitored, as unpatched RCE flaws are common entry points for ransomware and data breaches. The vendor's repeated critical flaws indicate systemic input validation issues that require active patching and monitoring.
Shame score — The flaw was actively exploited in the wild (KEV) and represents a repeated critical failure in input validation and secure coding practices by a vendor with a poor security track record.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
The PHP module within vBulletin contains an unspecified vulnerability that allows for remote code execution via the widgetConfig[code] parameter in an ajax/render/widget_php routestring request.
"The PHP module within vBulletin contains an unspecified vulnerability that allows for remote code execution via the widgetConfig[code] parameter in an ajax/render/widget_php routestring request."