CVE-2020-12720
62Vexday Risk Score
Patch now. It exploitation observed by VulnCheck and has a working public exploit.
ssvc Actepss 89%
from disclosure to weapon0 days
Published on NVDMay 7
metasploitMar 12
VulnCheck+340d
exploitation probability
89%top 1% of all CVEs
observed exploitation
yesVulnCheck
vBulletin before 5.5.6pl1, 5.6.0 before 5.6.0pl1, and 5.6.1 before 5.6.1pl1 has incorrect access control.
Affected products
n/a · n/aReferences
http://packetstormsecurity.com/files/157716/vBulletin-5.6.1-SQL-Injection.htmlhttp://packetstormsecurity.com/files/157904/vBulletin-5.6.1-SQL-Injection.htmlhttps://attackerkb.com/topics/RSDAFLik92/cve-2020-12720-vbulletin-incorrect-access-controlhttps://forum.vbulletin.com/forum/vbulletin-announcements/vbulletin-announcements_aa/4440032-vbulletin-5-6-1-security-patch-level-1