Vulnerability Description
In vBulletin before 5.3.0, remote attackers can bypass the CVE-2016-6483 patch and conduct SSRF attacks by leveraging the behavior of the PHP parse_url function, aka VBV-17037.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Vbulletin | Vbulletin | <= 5.2.6 |
Related Weaknesses (CWE)
References
- https://www.vbulletin.com/forum/forum/vbulletin-announcements/vbulletin-announceRelease NotesThird Party Advisory
- https://www.vbulletin.com/forum/forum/vbulletin-announcements/vbulletin-announceRelease NotesThird Party Advisory
FAQ
What is CVE-2017-7569?
CVE-2017-7569 is a vulnerability with a CVSS score of 8.6 (HIGH). In vBulletin before 5.3.0, remote attackers can bypass the CVE-2016-6483 patch and conduct SSRF attacks by leveraging the behavior of the PHP parse_url function, aka VBV-17037.
How severe is CVE-2017-7569?
CVE-2017-7569 has been rated HIGH with a CVSS base score of 8.6/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-7569?
Check the references section above for vendor advisories and patch information. Affected products include: Vbulletin Vbulletin.