CVE Vulnerabilities

CVE-2025-48827

Improper Protection of Alternate Path

Published: May 27, 2025 | Modified: Jun 25, 2025
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

vBulletin 5.0.0 through 5.7.5 and 6.0.0 through 6.0.3 allows unauthenticated users to invoke protected API controllers methods when running on PHP 8.1 or later, as demonstrated by the /api.php?method=protectedMethod pattern, as exploited in the wild in May 2025.

Weakness

The product does not sufficiently protect all possible paths that a user can take to access restricted functionality or resources.

Affected Software

NameVendorStart VersionEnd Version
VbulletinVbulletin5.0.0 (including)5.7.5 (including)
VbulletinVbulletin6.0.0 (including)6.0.3 (including)

Potential Mitigations

References