A critical security vulnerability has been discovered in the vBulletin forum software (versions 5.0.0 through 5.7.5 and 6.0.0 through 6.0.3). This vulnerability allows attackers without a forum account to execute malicious code on the server hosting the forum. This can lead to full server compromise, with potential exposure of sensitive data, website defacement, or the use of the server for further attacks. The issue is particularly relevant for forums running recent versions of PHP (8.1 and later) and is reportedly being actively exploited.
| Product | VBulletin |
| Date | 2025-06-02 16:14:45 |
| Information |
|
Technical Summary
vBulletin versions 5.0.0 through 5.7.5 and 6.0.0 through 6.0.3 are vulnerable to an unauthenticated Remote Code Execution (RCE) flaw. The root cause lies in inadequate authorization checks combined with the improper use of the PHP Reflection API, specifically affecting the ajax/api/ad/replaceAdTemplate endpoint.
The vulnerability, identified as CVE-2025-48827, allows unauthenticated users to invoke protected API controller methods when the software is running on PHP 8.1 or higher. This is because, starting with PHP 8.1, the behavior of reflection changed, potentially allowing access controls to be bypassed under certain conditions.
Attackers can exploit this vulnerability by sending a crafted POST request to the / path with the routestring parameter set to ajax/api/ad/replaceAdTemplate. In this request, it is possible to inject a malicious vBulletin template tag into the template parameter, such as <vb:if condition='" ... "'>, which can contain arbitrary PHP code, for example passthru($_POST['cmd']) or, as seen in the provided Nuclei template, var_dump("some_random_string") as a proof-of-concept.
A second POST request, also to / with routestring set to ajax/render/ad_<location> (where <location> matches the one used in the first request), triggers the rendering of the injected template, thereby executing the PHP code with the privileges of the web server user.
The exploit therefore utilizes a two-stage process: first to inject the malicious template code via replaceAdTemplate and then to render and execute it via ajax/render/ad_<location>. This allows an unauthenticated attacker to achieve remote code execution.
CVE-2025-48828 is also mentioned, likely referring to a closely related aspect of this vulnerability chain or the broader issue of protected method invocation.
Recommendations
- Update immediately: Update vBulletin to version 6.0.4 or later. If using vBulletin 5.x, apply all available security patches, particularly those addressing protected controller method invocation and securing the ad replacement functionality.
- Web Application Firewall (WAF): Implement WAF rules to block requests attempting to exploit this vulnerability. These rules could:
- Inspect the
routestringparameter to identify suspicious values such asajax/api/ad/replaceAdTemplateorajax/render/ad_. - Detect vBulletin template tags (
<vb:if>, etc.) containing PHP execution functions (e.g.,passthru,shell_exec,system,eval,exec,var_dump) within thetemplateparameter of thereplaceAdTemplatecall. - Block direct invocation of protected API methods if the WAF is capable of identifying such patterns.
- Inspect the
- PHP version considerations: While the exploitability is higher on PHP 8.1+, the underlying logical flaws may exist on older PHP versions as well. Do not rely on using an older version of PHP as a complete mitigation.
- Server log analysis: Monitor web server access logs and application logs for requests matching the exploit pattern (POST requests to
/withroutestring=ajax/api/ad/replaceAdTemplateorroutestring=ajax/render/ad_) to detect any compromise attempts.
Protect your organisation with Threat Intelligence and Digital Risk Protection.
Choose ISGroup for a practical, tailored engagement:
- A focused assessment of your environment and requirements
- Clear findings with a prioritised, actionable roadmap
- Direct support from experienced specialists through remediation and implementation
