{"id":11128,"date":"2025-05-31T22:01:23","date_gmt":"2025-05-31T22:01:23","guid":{"rendered":"https:\/\/usaontheweb.com\/clone1\/hackers-are-exploiting-critical-flaw-in-vbulletin-forum-software\/"},"modified":"2025-05-31T22:01:23","modified_gmt":"2025-05-31T22:01:23","slug":"hackers-are-exploiting-critical-flaw-in-vbulletin-forum-software","status":"publish","type":"post","link":"https:\/\/usaontheweb.com\/clone1\/hackers-are-exploiting-critical-flaw-in-vbulletin-forum-software\/","title":{"rendered":"Hackers are exploiting critical flaw in vBulletin forum software"},"content":{"rendered":"<p>Software <\/p>\n<div>\n<p><img loading=\"lazy\" decoding=\"async\" alt=\"software Box\" height=\"897\" src=\"https:\/\/www.bleepstatic.com\/content\/hl-images\/2024\/05\/07\/hacker-box.jpg\" width=\"1600\"><\/p>\n<p>Two critical vulnerabilities affecting the open-source forum software vBulletin have been discovered, with one confirmed to be actively exploited in the wild.<\/p>\n<p>The flaws, tracked under CVE-2025-48827 and CVE-2025-48828, and rated critical (CVSS v3 score: 10.0 and 9.0 respectively), are an API method invocation and a remote code execution (RCE) via template engine abuse flaws.<\/p>\n<p>They impact vBulletin versions 5.0.0 through 5.7.5 and 6.0.0 through 6.0.3 when the platform runs on PHP 8.1 or later.<\/p>\n<p>The vulnerabilities were likely patched quietly last year with the release of Patch Level 1 for all versions of the 6.* release branch, and version 5.7.5 Patch Level 3, but many sites remained exposed due to not upgrading.<\/p>\n<h2>Software Public PoC and active exploitation<\/h2>\n<p>The two issues were discovered on May 23, 2025, by security researcher Egidio Romano (EgiX), who explained how to exploit it via a detailed technical post on his blog.<\/p>\n<p>The researcher showed that the flaw lies in vBulletin&#8217;s misuse of PHP&#8217;s Reflection API, which, due to behavioral changes introduced in PHP 8.1, allows protected methods to be invoked without explicit accessibility adjustments.<\/p>\n<p>The vulnerability chain lies in the ability to invoke protected methods via crafted URLs and the misuse of template conditionals inside vBulletin&#8217;s template engine.<\/p>\n<p>By injecting crafted template code using the vulnerable &#8216;replaceAdTemplate&#8217; method, attackers bypass &#8220;unsafe function&#8221; filters using tricks like PHP variable function calls.<\/p>\n<p>This results in fully remote, unauthenticated code execution on the underlying server \u2014 effectively granting attackers shell access as the web server user (www-data on Linux, for example).<\/p>\n<p>On May 26, security researcher Ryan Dewhurst reported seeing exploitation attempts on honeypot logs showing requests to the vulnerable &#8216;ajax\/api\/ad\/replaceAdTemplate&#8217; endpoint.<\/p>\n<div>\n<figure><img loading=\"lazy\" decoding=\"async\" alt=\"software Logs showing exploitation attempts\" height=\"342\" src=\"https:\/\/www.bleepstatic.com\/images\/news\/u\/1220909\/2025\/May\/exploitation.png\" width=\"1200\"><figcaption><strong>Logs showing exploitation attempts<\/strong><br \/><em>Source:\u00a0blog.kevintel.com<\/em><\/figcaption><\/figure>\n<\/div>\n<p>Dewhurst traced one of the attackers to Poland, seeing attempts to deploy PHP backdoors to execute system commands.<\/p>\n<p>The researcher noted that the attacks appear to be leveraging the exploit published earlier by Romano, though there have been Nuclei templates available for the flaw since May 24, 2025.<\/p>\n<p>It is important to clarify that Dewhurst only observed exploitation attempts for CVE-2025-48827, but no evidence exists yet that attackers have successfully chained it to the full RCE, although this is highly likely.<\/p>\n<h2>Software vBulletin troubles<\/h2>\n<p>vBulletin is one of the most widely used commercial PHP\/MySQL-based forum platforms, powering thousands of online communities globally.<\/p>\n<p>Its modular design, including mobile APIs and AJAX interfaces, makes it a complex and flexible platform. However, it also exposes a broad attack surface.<\/p>\n<p>In the past, hackers have leveraged severe flaws in the platform to breach popular forums\u00a0and steal the sensitive data of large numbers of users.<\/p>\n<p>Forum administrators are recommended to apply the security updates for their vBulletin installation or move to the latest release, version 6.1.1, which is not affected by the said flaws.<\/p>\n<div>\n<p>\n            <img decoding=\"async\" src=\"https:\/\/www.bleepstatic.com\/c\/p\/picus\/red-report-in-article.jpg\" alt=\"software Red Report 2025\">\n    <\/p>\n<\/div><\/div>\n","protected":false},"excerpt":{"rendered":"<p>Software Two critical vulnerabilities affecting the open-source forum software vBulletin have been discovered, with one confirmed to be actively exploited<\/p>\n","protected":false},"author":7282,"featured_media":11129,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-11128","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-software"],"_links":{"self":[{"href":"https:\/\/usaontheweb.com\/clone1\/wp-json\/wp\/v2\/posts\/11128","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/usaontheweb.com\/clone1\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/usaontheweb.com\/clone1\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/usaontheweb.com\/clone1\/wp-json\/wp\/v2\/users\/7282"}],"replies":[{"embeddable":true,"href":"https:\/\/usaontheweb.com\/clone1\/wp-json\/wp\/v2\/comments?post=11128"}],"version-history":[{"count":0,"href":"https:\/\/usaontheweb.com\/clone1\/wp-json\/wp\/v2\/posts\/11128\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/usaontheweb.com\/clone1\/wp-json\/wp\/v2\/media\/11129"}],"wp:attachment":[{"href":"https:\/\/usaontheweb.com\/clone1\/wp-json\/wp\/v2\/media?parent=11128"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/usaontheweb.com\/clone1\/wp-json\/wp\/v2\/categories?post=11128"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/usaontheweb.com\/clone1\/wp-json\/wp\/v2\/tags?post=11128"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}