vBulletin before 5.6.9 PL1 allows an unauthenticated...
Critical severity
Unreviewed
Published
Feb 3, 2023
to the GitHub Advisory Database
•
Updated Feb 21, 2023
Description
Published by the National Vulnerability Database
Feb 3, 2023
Published to the GitHub Advisory Database
Feb 3, 2023
Last updated
Feb 21, 2023
vBulletin before 5.6.9 PL1 allows an unauthenticated remote attacker to execute arbitrary code via a crafted HTTP request that triggers deserialization. This occurs because verify_serialized checks that a value is serialized by calling unserialize and then checking for errors. The fixed versions are 5.6.7 PL1, 5.6.8 PL1, and 5.6.9 PL1.
References