CVE-2017-17672 | vBulletin up to 5.3.x cacheTemplates unserialize templateidlist deserialization (EDB-43362 / ID 860994)
A vulnerability was found in vBulletin up to 5.3.x. It has been declared as critical. Affected by this vulnerability is the function unserialize in the library vB_Library_Template's of the file ajax/api/template/cacheTemplates. The manipulation of the argument templateidlist as part of Parameter leads to deserialization.
This vulnerability is known as CVE-2017-17672. The attack can be launched remotely. Furthermore, there is an exploit available.