vBulletin before 5.6.9 PL1 allows an unauthenticated remote attacker to execute arbitrary code via a crafted HTTP request that triggers deserialization. This occurs because verify_serialized checks that a value is serialized by calling unserialize and then checking for errors. The fixed versions are 5.6.7 PL1, 5.6.8 PL1, and 5.6.9 PL1.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 26 Mar 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-03-26T14:52:17.030Z
Reserved: 2023-02-03T00:00:00.000Z
Link: CVE-2023-25135
Updated: 2024-08-02T11:18:35.592Z
Status : Modified
Published: 2023-02-03T05:15:10.737
Modified: 2025-03-26T15:15:47.997
Link: CVE-2023-25135
No data.
OpenCVE Enrichment
No data.
Weaknesses