Skip to content
COOEY

EXPOSURES › CVE-2020-17496

CVE-2020-17496

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2021-11-03 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2020-17496 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 78/100 rceexploited-in-wildunpatched

vBulletin's PHP module allowed remote code execution via crafted subWidgets data in an ajax/render/widget_tabbedcontainer_tab_panel request.

The vulnerability in vBulletin's PHP module enabled attackers to execute arbitrary code remotely by manipulating subWidgets data in specific requests. DIB organizations must care because this is an actively exploited vulnerability (KEV) that could compromise systems, leading to data breaches or ransomware attacks. Organizations should ensure all vBulletin instances are patched immediately and monitor for exploitation attempts.

Shame score — This is an actively exploited vulnerability (KEV) that allows remote code execution, indicating negligent patching and avoidable exposure to attackers.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

The PHP module within vBulletin contains an unspecified vulnerability that allows for remote code execution via crafted subWidgets data in an ajax/render/widget_tabbedcontainer_tab_panel request. This CVE ID resolves an incomplete patch for CVE-2019-16759.

SENTIMENT · TRUSTED SOURCES
synthesis severe-fallout -0.60
CISA KEV listing signals active exploitation, indicating severe fallout for vBulletin despite lack of explicit press condemnation in provided sources.
cooey ↗ severe-fallout -0.60
Neutral/Technical
"The PHP module within vBulletin contains an unspecified vulnerability that allows for remote code execution via crafted subWidgets data in an ajax/render/widget_tabbedcontainer_tab_panel request. This CVE ID resolves an incomplete patch for CVE-2019-16759."
socradar.io ↗ severe-fallout -0.60
Neutral/Technical
"CVE-2020-17496 vBulletin PHP Module Remote Code Execution Vulnerability vBulletin 5.5.4 through 5.6"
CISA ↗ severe-fallout -0.60
Neutral/Technical
"CISA Known Exploited Vulnerabilities (KEV) catalog is the authoritative list of security flaws that have been confirmed exploited in real-world attacks."
cvefeed.io ↗ severe-fallout -0.60
Neutral/Technical
"CVEFeed.io mirrors every entry, joins it to full CVE and severity data, and tracks new additions so you can prioritize remediation the moment a vulnerability enters the catalog."
www.cvefind.com ↗ severe-fallout -0.60
Neutral/Technical
"CISA Known Exploited Vulnerabilities (KEV) is an initiative that identifies and publishes a list of known exploited vulnerabilities."
kev.5sn.com ↗ severe-fallout -0.60
Neutral/Technical
"CVE-2020-17496 vBulletin PHP Module Remote Code Execution Vulnerability vBulletin 5.5.4 through 5.6"
NVD ↗ severe-fallout -0.60
Neutral/Technical
"NVD - Vulnerabilities"
AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.