The Admin CP in vBulletin 5.6.3 allows XSS via an Announcement Title to Channel Manager.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-25116
Reference (s):
- https://pentest-vincent.blogspot.com/2020/09/vbulletin-563-multiple-persistent-cross.html

