CyberSec.Space Logo
返回 CVE 瀏覽器

CVE-2025-48827

CRITICAL
10.0
CVSS Severity Score
EPSS Score0.0000%
EPSS Percentile0.00th
Published2025-05-27
Last Modified2026-06-17
Data SourcesNVD

Vulnerability Description

vBulletin 5.0.0 through 5.7.5 and 6.0.0 through 6.0.3 allows unauthenticated users to invoke protected API controllers' methods when running on PHP 8.1 or later, as demonstrated by the /api.php?method=protectedMethod pattern, as exploited in the wild in May 2025.

Affected Platforms (CPE)

📦
Vbulletin

Vbulletin

>= 5.0.0 and <= 5.7.5>= 6.0.0 and <= 6.0.3

References & Advisories

相關漏洞威脅