peter bassill · operator
$ cve CVE-2016-6483 JSON

CVE-2016-6483 EXPLOIT

8.6
HIGH · CVSS 3.0 · EPSS 11.9% (pctl 96)

Patch early

A public exploit exists.

Description

The media-file upload feature in vBulletin before 3.8.7 Patch Level 6, 3.8.8 before Patch Level 2, 3.8.9 before Patch Level 1, 4.x before 4.2.2 Patch Level 6, 4.2.3 before Patch Level 2, 5.x before 5.2.0 Patch Level 3, 5.2.1 before Patch Level 1, and 5.2.2 before Patch Level 1 allows remote attackers to conduct SSRF attacks via a crafted URL that results in a Redirection HTTP status code.

Scoring

CVSS8.6 (HIGH, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N
EPSS11.95% — more likely to be exploited than 96% of all CVEs
WeaknessCWE-918
On CISA KEVno
Public exploityes
Published2016-09-02
Last modified2026-06-17

Affected (1)

VendorProduct
vbulletinvbulletin

Public exploits

SourceTitleDate
exploit-dbvBulletin 5.2.2 - Server-Side Request Forgery2016-08-10

References

→ the Explorer  ·  watch your stack  ·  NVD