ASA-2019-00589 – vBulletin: Clickjacking Vulnerability


Allele Security Alert

ASA-2019-00589

Identifier(s)

ASA-2019-00589, CVE-2019-17131

Title

Clickjacking Vulnerability

Vendor(s)

vBulletin Solutions, Inc

Product(s)

vBulletin

Affected version(s)

vBulletin versions before 5.5.4

Fixed version(s)

vBulletin version 5.5.4

Proof of concept

Unknown

Description

vBulletin versions before 5.5.4 allow clickjacking.

Technical details

Unknown

Credits

Unknown

Reference(s)

vBulletin Connect 5.5.4 is now available for Download.
https://forum.vbulletin.com/forum/vbulletin-announcements/vbulletin-announcements_aa/4421373-vbulletin-connect-5-5-4-is-now-available-for-download

CVE-2019-17131
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-17131

CVE-2019-17131
https://nvd.nist.gov/vuln/detail/CVE-2019-17131

If there is any error in this alert or you wish a comprehensive analysis, let us know.

Last modified: October 25, 2019

We are not responsible for any data loss, device corruption or any other type of issue due to the use of any information mentioned in our security alerts.