Vulnerability record · CVE-2020-17496 · published 12 August 2020
CVE-2020-17496: vBulletin ajax render endpoint allows unauthenticated remote command execution
VVbulletin · Vbulletin
vBulletin 5.5.4 through 5.6.2 permits remote command execution through crafted subWidgets data sent to an ajax/render/widget_tabbedcontainer_tab_panel request. The flaw is an incomplete fix for CVE-2019-16759, so the earlier patch did not fully close the injection path. It matters because a public exploit exists and the issue is in CISA's Known Exploited Vulnerabilities catalog.
Description
vBulletin 5.5.4 through 5.6.2 allows remote command execution via crafted subWidgets data in an ajax/render/widget_tabbedcontainer_tab_panel request. NOTE: this issue exists because of an incomplete fix for CVE-2019-16759.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated network remote code execution with public exploit code, KEV listing and very high EPSS probability.
What it is
vBulletin 5.5.4 through 5.6.2 permits remote command execution through crafted subWidgets data sent to an ajax/render/widget_tabbedcontainer_tab_panel request. The flaw is an incomplete fix for CVE-2019-16759, so the earlier patch did not fully close the injection path. It matters because a public exploit exists and the issue is in CISA's Known Exploited Vulnerabilities catalog.
Impact
An unauthenticated attacker can execute arbitrary commands on the web server, leading to full compromise of the vBulletin host and any data or credentials it holds.
Attack surface
Reachable over the network via a crafted HTTP request to the ajax/render/widget_tabbedcontainer_tab_panel endpoint; the CVSS vector shows no privileges or user interaction required.
Exploitation
Listed in CISA KEV since 2021-11-03 with a required action to apply vendor updates, and EPSS gives a 30-day probability of 0.8774 (99.75th percentile). Multiple references are tagged Exploit, indicating public exploit code is available.
What to do
- Apply the vendor security patch for vBulletin 5.6.0/5.6.1/5.6.2 or upgrade to a fixed release immediately.
- If patching cannot be done at once, restrict or block external access to the ajax/render/widget_tabbedcontainer_tab_panel endpoint.
- Place the forum behind a WAF or reverse proxy with rules blocking crafted subWidgets parameters.
- Audit the host for signs of compromise and rotate credentials and secrets stored on the server.
- Confirm the CVE-2019-16759 fix is fully applied, since this issue is an incomplete fix of that one.
Detection
- Search web logs for POST requests to ajax/render/widget_tabbedcontainer_tab_panel containing subWidgets parameters.
- Monitor for unexpected outbound connections or child processes spawned by the web server user.
- Alert on file writes or new files in web-accessible directories on the vBulletin host.
- Review for webshell artifacts and unusual PHP files in the forum installation.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2020-17496 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "vBulletin PHP Module Remote Code Execution Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 3 May 2022.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://blog.exploitee.rs/2020/exploiting-vbulletin-a-tale-of-patch-fail/ | ExploitThird Party Advisory |
| https://cwe.mitre.org/data/definitions/78.html | Technical Description |
| https://forum.vbulletin.com/forum/vbulletin-announcements/vbulletin-announcements_aa/4445227-vbulletin-5-6-0-5-6-1-5-6-2 | PatchVendor Advisory |
| https://seclists.org/fulldisclosure/2020/Aug/5 | ExploitMailing ListThird Party Advisory |
| https://blog.exploitee.rs/2020/exploiting-vbulletin-a-tale-of-patch-fail/ | ExploitThird Party Advisory |
| https://cwe.mitre.org/data/definitions/78.html | Technical Description |
| https://forum.vbulletin.com/forum/vbulletin-announcements/vbulletin-announcements_aa/4445227-vbulletin-5-6-0-5-6-1-5-6-2 | PatchVendor Advisory |
| https://seclists.org/fulldisclosure/2020/Aug/5 | ExploitMailing ListThird Party Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-17496 | US Government Resource |
Track CVE-2020-17496 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-17496), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.