EXPOSURES › CVE-2020-17496
CVE-2020-17496
HIGH ⌖ ON CISA KEV · EXPLOITEDvBulletin's PHP module allowed remote code execution via crafted subWidgets data in an ajax/render/widget_tabbedcontainer_tab_panel request.
The vulnerability in vBulletin's PHP module enabled attackers to execute arbitrary code remotely by manipulating subWidgets data in specific requests. DIB organizations must care because this is an actively exploited vulnerability (KEV) that could compromise systems, leading to data breaches or ransomware attacks. Organizations should ensure all vBulletin instances are patched immediately and monitor for exploitation attempts.
Shame score — This is an actively exploited vulnerability (KEV) that allows remote code execution, indicating negligent patching and avoidable exposure to attackers.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
The PHP module within vBulletin contains an unspecified vulnerability that allows for remote code execution via crafted subWidgets data in an ajax/render/widget_tabbedcontainer_tab_panel request. This CVE ID resolves an incomplete patch for CVE-2019-16759.
"The PHP module within vBulletin contains an unspecified vulnerability that allows for remote code execution via crafted subWidgets data in an ajax/render/widget_tabbedcontainer_tab_panel request. This CVE ID resolves an incomplete patch for CVE-2019-16759."
"CVE-2020-17496 vBulletin PHP Module Remote Code Execution Vulnerability vBulletin 5.5.4 through 5.6"
"CISA Known Exploited Vulnerabilities (KEV) catalog is the authoritative list of security flaws that have been confirmed exploited in real-world attacks."
"CVEFeed.io mirrors every entry, joins it to full CVE and severity data, and tracks new additions so you can prioritize remediation the moment a vulnerability enters the catalog."
"CISA Known Exploited Vulnerabilities (KEV) is an initiative that identifies and publishes a list of known exploited vulnerabilities."
"CVE-2020-17496 vBulletin PHP Module Remote Code Execution Vulnerability vBulletin 5.5.4 through 5.6"