CVE-2025-48827

vBulletin 5.0.0 through 5.7.5 and 6.0.0 through 6.0.3 allows unauthenticated users to invoke protected API controllers' methods when running on PHP 8.1 or later, as demonstrated by the /api.php?method=protectedMethod pattern, as exploited in the wild in May 2025.
Configurations

No configuration.

History

27 May 2025, 18:15

Type Values Removed Values Added
References
  • () https://blog.kevintel.com/vbulletin-replaceadtemplate-kev/ -
References () https://karmainsecurity.com/dont-call-that-protected-method-vbulletin-rce - () https://karmainsecurity.com/dont-call-that-protected-method-vbulletin-rce -

27 May 2025, 14:15

Type Values Removed Values Added
References () https://karmainsecurity.com/dont-call-that-protected-method-vbulletin-rce - () https://karmainsecurity.com/dont-call-that-protected-method-vbulletin-rce -

27 May 2025, 13:15

Type Values Removed Values Added
Summary
  • (es) vBulletin 5.0.0 a 5.7.5 y 6.0.0 a 6.0.3 permite a usuarios no autenticados invocar métodos de controladores de API protegidos cuando se ejecutan en PHP 8.1 o posterior, como lo demuestra el patrón /api.php?method=protectedMethod.
Summary (en) vBulletin 5.0.0 through 5.7.5 and 6.0.0 through 6.0.3 allows unauthenticated users to invoke protected API controllers' methods when running on PHP 8.1 or later, as demonstrated by the /api.php?method=protectedMethod pattern. (en) vBulletin 5.0.0 through 5.7.5 and 6.0.0 through 6.0.3 allows unauthenticated users to invoke protected API controllers' methods when running on PHP 8.1 or later, as demonstrated by the /api.php?method=protectedMethod pattern, as exploited in the wild in May 2025.
References
  • () https://kevintel.com/CVE-2025-48827 -

27 May 2025, 04:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-05-27 04:15

Updated : 2025-05-28 15:01


NVD link : CVE-2025-48827

Mitre link : CVE-2025-48827

CVE.ORG link : CVE-2025-48827


JSON object : View

Products Affected

No product.

CWE
CWE-424

Improper Protection of Alternate Path