ID:11734 - Exploit for Improper protection of alternate path in vBulletin - CVE-2025-48827
Published: June 29, 2025
vBulletin
Link to public exploit:
Vulnerability description
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to missing authorization checks within protected API controllers methods. A remote non-authenticated attacker can send a specially crafted request to the website and execute arbitrary PHP code on the system.
Successful exploitation of the vulnerability requires PHP 8.1 to be used by the web application.