Description
An SQL injection vulnerability affects vBulletin 5.6.1 and earlier versions. The SQL injection vulnerability affects the vBulletin endpoint /ajax/api/content_infraction/getIndexableContent and can be exploited via the POST parameter nodeId[nodeid].
The following patches are available for the following versions of vBulletin Connect:
- 5.6.1 Patch Level 1
- 5.6.0 Patch Level 1
- 5.5.6 Patch Level 1
If you are using a version of vBulletin 5 Connect prior to 5.5.6, it is imperative that you upgrade as soon as possible.
Remediation
Upgrade to the latest version of vBulletin 5.
References
Related Vulnerabilities
WordPress Plugin WP-PostRatings '[ratings]' Shortcode SQL Injection (1.61)
WordPress Plugin iCopyright Toolbar 'icopyright_xml.php' SQL Injection (1.1.4)
WordPress Plugin Answer My Question SQL Injection (1.3)
WordPress Plugin Server Status by Hostname/IP SQL Injection (4.6)
WordPress Plugin Wow Forms-create any form with custom style SQL Injection (2.1)