CVE-2017-17672
critical · 9.8In vBulletin through 5.3.x, there is an unauthenticated deserialization vulnerability that leads to arbitrary file deletion and, under certain circumstances, code execution, because of unsafe usage of PHP's unserialize() in vB_Library_Template's cacheTemplates() function, which is a publicly exposed API. This is exploited with the templateidlist parameter to ajax/api/template/cacheTemplates.
9.8
CVSS
15.2%
EPSS (exploit prob.)
97th
EPSS percentile
2017-12-14
Published
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-502
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| vbulletin | vbulletin | >= 5.0.1, <= 5.3.3 |
| vbulletin | vbulletin | 5.0.0 |
| vbulletin | vbulletin | 5.0.0 |
Check a specific version with /api/v1/cve/match.
References
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2017-17672