VYPR
Unrated severityCISA KEVNVD Advisory· Published Aug 12, 2020· Updated Oct 21, 2025

CVE-2020-17496

CVE-2020-17496

Description

vBulletin 5.5.4 through 5.6.2 allows remote command execution via crafted subWidgets data in an ajax/render/widget_tabbedcontainer_tab_panel request. NOTE: this issue exists because of an incomplete fix for CVE-2019-16759.

Affected products

1
  • vBulletin/vBulletindescription

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

4

News mentions

0

No linked articles in our index yet.