
VBulletin is one of the most popular and widely used forum, written in PHP and used by a wide range of organizations.
Considering that vBulletin is used by over 100,000 websites, it makes sense that it has become a popular target for hackers.
And now a critical vulnerability has been discovered in it, which can be exploited by malicious actors, so it is very important for users to install the new update immediately.
Last September, an anonymous hacker publicly disclosed a zero-day flaw in the software.
After the disclosure, many malicious actors exploited this bug (CVE-2019-16759) to gain access to various forums and managed to obtain sensitive details such as username, email address, last IP used to access the forums, etc
vBulletin software
The vulnerability was discovered by Charles Fol, a security engineer at Ambionics. However, he did not reveal any further details. More information about the vulnerability is expected to be released at the SSTIC, which will take place on June 3-5.
CVE -2020-12720 is an access control vulnerability and Fol rates it as critical.
To fix the bug, vBulletin released a new security patch
5.6.1 Patch Level 1
5.6.0 Patch Level 1
5.5.6 Patch Level 1
If you are using a version of vBulletin 5 Connect prior to 5.5.6, it is recommended that you upgrade to newer versions. The company also states that “the security patch has already been applied to all vBulletin Cloud sites.”
