CVE-2025-48827

vBulletin 5.0.0 through 5.7.5 and 6.0.0 through 6.0.3 allows unauthenticated users to invoke protected API controllers' methods when running on PHP 8.1 or later, as demonstrated by the /api.php?method=protectedMethod pattern, as exploited in the wild in May 2025.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:vbulletin:vbulletin:*:*:*:*:*:*:*:*
cpe:2.3:a:vbulletin:vbulletin:*:*:*:*:*:*:*:*

History

25 Jun 2025, 16:46

Type Values Removed Values Added
References () https://karmainsecurity.com/dont-call-that-protected-method-vbulletin-rce - () https://karmainsecurity.com/dont-call-that-protected-method-vbulletin-rce - Exploit, Third Party Advisory
References () https://kevintel.com/CVE-2025-48827 - () https://kevintel.com/CVE-2025-48827 - Third Party Advisory
References () https://blog.kevintel.com/vbulletin-replaceadtemplate-kev/ - () https://blog.kevintel.com/vbulletin-replaceadtemplate-kev/ - Broken Link
CPE cpe:2.3:a:vbulletin:vbulletin:*:*:*:*:*:*:*:*
First Time Vbulletin
Vbulletin vbulletin

27 May 2025, 18:15

Type Values Removed Values Added
References
  • () https://blog.kevintel.com/vbulletin-replaceadtemplate-kev/ -
References () https://karmainsecurity.com/dont-call-that-protected-method-vbulletin-rce - () https://karmainsecurity.com/dont-call-that-protected-method-vbulletin-rce -

27 May 2025, 14:15

Type Values Removed Values Added
References () https://karmainsecurity.com/dont-call-that-protected-method-vbulletin-rce - () https://karmainsecurity.com/dont-call-that-protected-method-vbulletin-rce -

27 May 2025, 13:15

Type Values Removed Values Added
References
  • () https://kevintel.com/CVE-2025-48827 -
Summary
  • (es) vBulletin 5.0.0 a 5.7.5 y 6.0.0 a 6.0.3 permite a usuarios no autenticados invocar métodos de controladores de API protegidos cuando se ejecutan en PHP 8.1 o posterior, como lo demuestra el patrón /api.php?method=protectedMethod.
Summary (en) vBulletin 5.0.0 through 5.7.5 and 6.0.0 through 6.0.3 allows unauthenticated users to invoke protected API controllers' methods when running on PHP 8.1 or later, as demonstrated by the /api.php?method=protectedMethod pattern. (en) vBulletin 5.0.0 through 5.7.5 and 6.0.0 through 6.0.3 allows unauthenticated users to invoke protected API controllers' methods when running on PHP 8.1 or later, as demonstrated by the /api.php?method=protectedMethod pattern, as exploited in the wild in May 2025.

27 May 2025, 04:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-05-27 04:15

Updated : 2025-06-25 16:46


NVD link : CVE-2025-48827

Mitre link : CVE-2025-48827

CVE.ORG link : CVE-2025-48827


JSON object : View

Products Affected

vbulletin

  • vbulletin
CWE
CWE-424

Improper Protection of Alternate Path