HomeSecurityCritical vulnerabilities fixed in vBulletin software

Critical vulnerabilities fixed in vBulletin software

vBulletin

VBulletin is one of the most popular and widely used forum, written in PHP and used by a wide range of organizations.

Considering that vBulletin is used by over 100,000 websites, it makes sense that it has become a popular target for hackers.

And now a critical vulnerability has been discovered in it, which can be exploited by malicious actors, so it is very important for users to install the new update immediately.

Last September, an anonymous hacker publicly disclosed a zero-day flaw in the software.

After the disclosure, many malicious actors exploited this bug (CVE-2019-16759) to gain access to various forums and managed to obtain sensitive details such as username, email address, last IP used to access the forums, etc

vBulletin software

The vulnerability was discovered by Charles Fol, a security engineer at Ambionics. However, he did not reveal any further details. More information about the vulnerability is expected to be released at the SSTIC, which will take place on June 3-5.

CVE -2020-12720 is an access control vulnerability and Fol rates it as critical.

To fix the bug, vBulletin released a new security patch

5.6.1 Patch Level 1

5.6.0 Patch Level 1

5.5.6 Patch Level 1

If you are using a version of vBulletin 5 Connect prior to 5.5.6, it is recommended that you upgrade to newer versions. The company also states that “the security patch has already been applied to all vBulletin Cloud sites.”

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS