CVE-2023-25135

Severity CVSS v4.0:
Pending analysis
Type:
CWE-502 Deserialization of Untrusted Dat
Publication date:
03/02/2023
Last modified:
26/03/2025

Description

vBulletin before 5.6.9 PL1 allows an unauthenticated remote attacker to execute arbitrary code via a crafted HTTP request that triggers deserialization. This occurs because verify_serialized checks that a value is serialized by calling unserialize and then checking for errors. The fixed versions are 5.6.7 PL1, 5.6.8 PL1, and 5.6.9 PL1.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:vbulletin:vbulletin:5.6.7:-:*:*:*:*:*:*
cpe:2.3:a:vbulletin:vbulletin:5.6.8:-:*:*:*:*:*:*
cpe:2.3:a:vbulletin:vbulletin:5.6.9:-:*:*:*:*:*:*