Loading HuntDB...

GHSA-23fp-mrfv-cwv4

GitHub Security Advisory

⚠ Unreviewed CRITICAL Has CVE

Advisory Details

vBulletin 5.0.0 through 5.7.5 and 6.0.0 through 6.0.3 allows unauthenticated users to invoke protected API controllers' methods when running on PHP 8.1 or later, as demonstrated by the /api.php?method=protectedMethod pattern.

Related CVEs

Key Information

GHSA ID
GHSA-23fp-mrfv-cwv4
Published
May 27, 2025 6:30 AM
Last Modified
May 27, 2025 6:30 PM
CVSS Score
9.0 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: July 1, 2025 6:26 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.