VYPR
Critical severity9.8NVD Advisory· Published Oct 30, 2020· Updated Jun 17, 2026

CVE-2020-7373

CVE-2020-7373

Description

vBulletin 5.5.4 through 5.6.2 allows remote command execution via crafted subWidgets data in an ajax/render/widget_tabbedcontainer_tab_panel request. NOTE: this issue exists because of an incomplete fix for CVE-2019-16759. ALSO NOTE: CVE-2020-7373 is a duplicate of CVE-2020-17496. CVE-2020-17496 is the preferred CVE ID to track this vulnerability.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • Jelsoft/Vbulletin2 versions
    cpe:2.3:a:vbulletin:vbulletin:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:vbulletin:vbulletin:*:*:*:*:*:*:*:*range: >=5.5.4,<=5.6.2
    • (no CPE)range: 5.5.4 - 5.6.2
  • vBulletin/vBulletindescription

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.