cve/2019/CVE-2019-16759.md
2024-06-18 02:51:15 +02:00

4.2 KiB

CVE-2019-16759

Description

vBulletin 5.x through 5.5.4 allows remote command execution via the widgetConfig[code] parameter in an ajax/render/widget_php routestring request.

POC

Reference

Github