Description
An SQL injection vulnerability affects vBulletin 5.6.1 and earlier versions. The SQL injection vulnerability affects the vBulletin endpoint /ajax/api/content_infraction/getIndexableContent and can be exploited via the POST parameter nodeId[nodeid].
The following patches are available for the following versions of vBulletin Connect:
- 5.6.1 Patch Level 1
- 5.6.0 Patch Level 1
- 5.5.6 Patch Level 1
If you are using a version of vBulletin 5 Connect prior to 5.5.6, it is imperative that you upgrade as soon as possible.
Remediation
Upgrade to the latest version of vBulletin 5.
References
Related Vulnerabilities
Agentejo Cockpit CMS resetpassword NoSQLi (CVE-2020-35847)
WordPress Plugin Simple Login Log SQL Injection (1.1.1)
WordPress Plugin Affiliates Manager SQL Injection (2.8.6)
WordPress Plugin GigPress Multiple SQL Injection Vulnerabilities (2.3.8)
WordPress Plugin Quiz Maker Multiple SQL Injection Vulnerabilities (6.2.0.8)