Critical Zero-Day Pre-authentication Remote Code Execution Exploit Published for 5.x Versions of vBulletin
by Ryan Seguin on September 24, 2019
New critical zero-day pre-auth RCE exploit code published on Full Disclosure mailing list for 5.x versions of vBulletin (CVE-2019-16759).
UPDATE 09/25/2019: The background and solution sections below have been updated to reflect the security patch issued by the vBulletin team.