Vulnerability record · CVE-2020-7373 · published 30 October 2020
CVE-2020-7373: vBulletin ajax/render widget subWidgets remote code execution
VVbulletin · Vbulletin
vBulletin 5.5.4 through 5.6.2 allows remote command execution through crafted subWidgets data in an ajax/render/widget_tabbedcontainer_tab_panel request. The flaw is an incomplete fix for CVE-2019-16759 and is a duplicate of CVE-2020-17496, which is the preferred tracking ID. It matters because unauthenticated attackers can execute code on exposed forums.
Description
vBulletin 5.5.4 through 5.6.2 allows remote command execution via crafted subWidgets data in an ajax/render/widget_tabbedcontainer_tab_panel request. NOTE: this issue exists because of an incomplete fix for CVE-2019-16759. ALSO NOTE: CVE-2020-7373 is a duplicate of CVE-2020-17496. CVE-2020-17496 is the preferred CVE ID to track this vulnerability.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with no authentication or user interaction, public exploit code, and very high EPSS make this an urgent remote code execution risk.
What it is
vBulletin 5.5.4 through 5.6.2 allows remote command execution through crafted subWidgets data in an ajax/render/widget_tabbedcontainer_tab_panel request. The flaw is an incomplete fix for CVE-2019-16759 and is a duplicate of CVE-2020-17496, which is the preferred tracking ID. It matters because unauthenticated attackers can execute code on exposed forums.
Impact
An attacker can execute arbitrary commands on the server, leading to full compromise of the vBulletin host and any data it holds. No privileges are required.
Attack surface
Reachable over the network via HTTP requests to the ajax/render/widget_tabbedcontainer_tab_panel endpoint. The CVSS vector shows no authentication (PR:N) and no user interaction (UI:N).
Exploitation
Public exploit code and a Metasploit module exist per reference tags, and EPSS is 0.45 (98.7th percentile), indicating high likelihood of exploitation. It is not listed in CISA KEV.
What to do
- Upgrade vBulletin to a version that includes the complete fix for CVE-2020-17496 (the preferred CVE for this issue).
- If immediate upgrade is not possible, restrict or block access to the ajax/render/widget_tabbedcontainer_tab_panel endpoint at the web server or WAF.
- Apply the vendor security patch referenced in the vBulletin announcement.
- Monitor for and remove any web shells or unauthorized files left by prior exploitation.
- Review server logs for suspicious requests to the vulnerable endpoint.
Detection
- Search HTTP access logs for requests to ajax/render/widget_tabbedcontainer_tab_panel with unusual subWidgets parameters.
- Monitor for outbound connections or process creation from the web server user that indicate command execution.
- Use file integrity monitoring on the vBulletin web root to detect newly written files or modifications.
- Alert on Metasploit or known exploit payload patterns in request bodies.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://blog.exploitee.rs/2020/exploiting-vbulletin-a-tale-of-patch-fail/ | ExploitThird Party Advisory |
| https://forum.vbulletin.com/forum/vbulletin-announcements/vbulletin-announcements_aa/4445227-vbulletin-5-6-0-5-6-1-5-6-2 | PatchVendor Advisory |
| https://github.com/rapid7/metasploit-framework/pull/13970 | PatchThird Party Advisory |
| https://seclists.org/fulldisclosure/2020/Aug/5 | ExploitMailing ListThird Party Advisory |
| https://blog.exploitee.rs/2020/exploiting-vbulletin-a-tale-of-patch-fail/ | ExploitThird Party Advisory |
| https://forum.vbulletin.com/forum/vbulletin-announcements/vbulletin-announcements_aa/4445227-vbulletin-5-6-0-5-6-1-5-6-2 | PatchVendor Advisory |
| https://github.com/rapid7/metasploit-framework/pull/13970 | PatchThird Party Advisory |
| https://seclists.org/fulldisclosure/2020/Aug/5 | ExploitMailing ListThird Party Advisory |
Track CVE-2020-7373 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-7373), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.