CVE-2019-16759 KEV EXPLOIT
9.8
CRITICAL · CVSS 3.1 · EPSS 99.7% (pctl 100)
Patch first
On CISA KEV — known exploited in the wild, due 2022-05-03.
Description
vBulletin 5.x through 5.5.4 allows remote command execution via the widgetConfig[code] parameter in an ajax/render/widget_php routestring request.
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 99.73% — more likely to be exploited than 100% of all CVEs |
| Weakness | CWE-94 |
| On CISA KEV | yes — remediate by 2022-05-03 |
| Public exploit | yes |
| Published | 2019-09-24 |
| Last modified | 2026-06-17 |
CISA KEV
| Name | vBulletin PHP Module Remote Code Execution Vulnerability |
|---|---|
| Added | 2021-11-03 |
| Due | 2022-05-03 |
| Vendor / product | vBulletin / vBulletin |
| Ransomware use | none reported |
Affected (1)
| Vendor | Product |
|---|---|
| vbulletin | vbulletin |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | vBulletin 5.x - Remote Command Execution (Metasploit) | 2019-09-30 |
| exploit-db | vBulletin 5.0 < 5.5.4 - 'widget_php ' Unauthenticated Remote Code Execution | 2019-09-23 |
References
- http://packetstormsecurity.com/files/154623/vBulletin-5.x-0-Day-Pre-Auth-Remote-Command-Execution.html
- http://packetstormsecurity.com/files/154648/vBulletin-5.x-Pre-Auth-Remote-Code-Execution.html
- http://packetstormsecurity.com/files/155633/vBulletin-5.5.4-Remote-Command-Execution.html
- http://packetstormsecurity.com/files/158829/vBulletin-5.x-Remote-Code-Execution.html
- http://packetstormsecurity.com/files/158830/vBulletin-5.x-Remote-Code-Execution.html
- http://packetstormsecurity.com/files/158866/vBulletin-5.x-Remote-Code-Execution.html
- http://seclists.org/fulldisclosure/2020/Aug/5
- https://arstechnica.com/information-technology/2019/09/public-exploit-code-spawns-mass-attacks-against-high-severity-vbulletin-bug/
- https://seclists.org/fulldisclosure/2019/Sep/31
- https://www.theregister.co.uk/2019/09/24/vbulletin_vbug_zeroday/
- http://packetstormsecurity.com/files/154623/vBulletin-5.x-0-Day-Pre-Auth-Remote-Command-Execution.html
- http://packetstormsecurity.com/files/154648/vBulletin-5.x-Pre-Auth-Remote-Code-Execution.html
- http://packetstormsecurity.com/files/155633/vBulletin-5.5.4-Remote-Command-Execution.html
- http://packetstormsecurity.com/files/158829/vBulletin-5.x-Remote-Code-Execution.html
- http://packetstormsecurity.com/files/158830/vBulletin-5.x-Remote-Code-Execution.html
- http://packetstormsecurity.com/files/158866/vBulletin-5.x-Remote-Code-Execution.html
- http://seclists.org/fulldisclosure/2020/Aug/5
- https://arstechnica.com/information-technology/2019/09/public-exploit-code-spawns-mass-attacks-against-high-severity-vbulletin-bug/
- https://seclists.org/fulldisclosure/2019/Sep/31
- https://www.theregister.co.uk/2019/09/24/vbulletin_vbug_zeroday/
→ the Explorer · watch your stack · NVD