XSS Vulnerability in vBulletin 5.6.3 Admin CP via Child Help Item Title

XSS Vulnerability in vBulletin 5.6.3 Admin CP via Child Help Item Title

CVE-2020-25119 · MEDIUM Severity

CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N

The Admin CP in vBulletin 5.6.3 allows XSS via a Title of a Child Help Item in the Login/Logoff part of the User Manual.

Learn more about our User Device Pen Test.