CVE-2014-2021

vBulletin < 4.2.2 and 5.0.x-5.0.5 - Authenticated Stored Cross-Site Scripting via XMLRPC API Client Name

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2014-2021. PoCs published by tintinweb.

AI-analyzed exploit summary This exploit demonstrates a persistent XSS vulnerability in vBulletin 4.x/5.x via the xmlrpc API. It injects malicious JavaScript into the admin control panel's API log page, which executes when an admin views the log and clicks on the client name.

Description

Cross-site scripting (XSS) vulnerability in admincp/apilog.php in vBulletin 4.2.2 and earlier, and 5.0.x through 5.0.5 allows remote authenticated users to inject arbitrary web script or HTML via a crafted XMLRPC API request, as demonstrated using the client name.

Exploits (1)

exploitdb WORKING POC
by tintinweb · pythonwebappsphp
https://www.exploit-db.com/exploits/40114

This exploit demonstrates a persistent XSS vulnerability in vBulletin 4.x/5.x via the xmlrpc API. It injects malicious JavaScript into the admin control panel's API log page, which executes when an admin views the log and clicks on the client name.

Classification
Working Poc 95%
Attack Type
Xss
Complexity
Moderate
Reliability
Reliable
Target: vBulletin 4.x/5.x
Auth required
Prerequisites: API interface enabled · API logging enabled · Valid API key · Admin interaction to trigger payload
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (7)

Core 7
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1031000
Mailing List mailing-list x_refsource_fulldisc
http://seclists.org/fulldisclosure/2014/Oct/63
Exploit mailing-list x_refsource_fulldisc
http://seclists.org/fulldisclosure/2014/Oct/55
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/97026
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/70577

Scores

EPSS 0.0339
EPSS Percentile 87.3%

Details

CWE
CWE-79
Status published
Products (7)
vbulletin/vbulletin 5.0.0
vbulletin/vbulletin 5.0.1
vbulletin/vbulletin 5.0.2
vbulletin/vbulletin 5.0.3
vbulletin/vbulletin 5.0.4
vbulletin/vbulletin 5.0.5
vbulletin/vbulletin < 4.2.2
Published Oct 25, 2014
Tracked Since Feb 18, 2026