CVE-2014-9438: vBulletin
Medium severity, CVSS 6.8. EPSS: 1.1% chance of exploitation in the next 30 days.
Cross-site request forgery (CSRF) vulnerability in the Moderator Control Panel in vBulletin 4.2.2 allows remote attackers to hijack the authentication of administrators for requests that (1) ban a user via the username parameter in a dobanuser action to modcp/banning.php or (2) unban a user, (3) modify user profiles, edit a (4) post or (5) topic, or approve a (6) post or (7) topic via unspecified vectors.
Affected products
- vBulletin vBulletin: version 4.2.2 only
Published 2015-01-02. Last modified 2026-06-17.