The versions listed below are known to be affected by this issue. If you are using one of those versions, you should update to a newer release that has no known vulnerabilities.
Common Name None VWE-ID VWE-2017-4032 Related Report None Severity MEDIUM Exploit Difficulty EASY Platform vBulletin Description Permissions escalation. Users may be able to upload images that exceed maximum allowed dimensions and/or file-size if admin has chosen to store the binary data of uploaded attachments in the database. Does not affect Lite versions.
Discovered September 20, 2017 Resolved September 24, 2017 Patches Available 4.0.19 Patch Level 2
4.0.18 Patch Level 3
4.0.17 Patch Level 5
4.0.16 Patch Level 6
4.0.15 Patch Level 10
Workaround In the Wiki Admin Panel, go to Content > Attachments, and make sure that attachments are stored as files.
Categories: XSS:4.0.0, XSS:4.0.0 Alpha 1, XSS:4.0.0 Alpha 2, XSS:4.0.0 Alpha 3, XSS:4.0.0 Alpha 4, XSS:4.0.0 Alpha 5, XSS:4.0.0 Alpha 6, XSS:4.0.0 Alpha 7, XSS:4.0.0 Beta 1, XSS:4.0.0 Beta 2, XSS:4.0.0 Beta 3, XSS:4.0.0 Beta 4, XSS:4.0.0 Beta 5, XSS:4.0.0 Beta 6, XSS:4.0.0 Beta 7, XSS:4.0.0 Gamma 1, XSS:4.0.0 Gamma 2, XSS:4.0.0 Gamma 3, XSS:4.0.0 Gamma 4, XSS:4.0.0 Gamma 5, XSS:4.0.0 Gamma 6, XSS:4.0.0 Gamma 7, XSS:4.0.0 Patch Level 1, XSS:4.0.0 Patch Level 2, XSS:4.0.0 Patch Level 3, More…