As cited
Copy frozen at (site build).
vulnerabilities
vBulletin fixes critical pre-auth RCE flaw with public exploit
vBulletin released a patch for a critical pre-authentication remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary PHP code via template rendering. The flaw affects the forum software and carries a public exploit.
Why it matters: Organizations running vBulletin forums must apply the patch immediately, as unauthenticated attackers can exploit this publicly disclosed vulnerability to gain code execution on affected systems.
- Source published
- First seen by Cybersecurity Tracker