CVE-2019-17271
vBulletin 5.5.4 allows SQL Injection via the ajax/api/hook/getHookList or ajax/api/widget/getWidgetList where parameter.
vBulletin 5.5.4 allows SQL Injection via the ajax/api/hook/getHookList or ajax/api/widget/getWidgetList where parameter.
MEDIUM · CVSS 4.9
EPSS 0.00347
Schedule remediation
- Public exploit or PoC is available
Sigma rules0
YARA rules0