vBulletin has announced the release of a security update for its eponymous forum creation software, which aims to fix a SQL injection.
The risk of SQL Injection attacks was privately reported by members of the Romanian Security Team (RST) last week. The vulnerability was discovered while testing vBulletin version 5.x for security issues.
One of the researchers says that a potential attacker could, through this specific security flaw, gain access to the database that contains information about administrators.
This would provide access to the admin panel and by extension other databases. In addition to login details and email addresses, some websites also maintain databases with financial information, which would be a treasure trove for any attacker.
The current security update covers versions 5.0.4, 5.0.5, 5.1.0, 5.1.1 and 5.1.2. Patches for all versions are available on this page and users are advised to install the updates as soon as possible.

