CVE-2019-16759 | vBulletin up to 5.5.4 ajax/render/widget_php widgetConfig[code] code injection (ID 154623 / EDB-47447)
A vulnerability was found in vBulletin up to 5.5.4. It has been classified as critical. This affects an unknown part of the file ajax/render/widget_php. The manipulation of the argument widgetConfig[code] as part of Parameter leads to code injection.
This vulnerability is uniquely identified as CVE-2019-16759. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.