CVE-2014-125084 is a critical SQL injection vulnerability affecting Gimmie Plugin version 1.2.2 on vBulletin, specifically within the trigger_referral.php file via the referrername argument. This flaw carries a CVSS score of 9.8, indicating a high potential for complete compromise of confidentiality, integrity, and availability, with an easily exploitable network-based attack vector requiring no user interaction. While there are no known public exploits in Metasploit or ExploitDB, the vulnerability has garnered significant community discussion, suggesting awareness among security researchers. Upgrading to Gimmie Plugin version 1.3.0 is recommended to remediate this issue.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.3.0CPE matchmatch criteria | cpe:2.3:a:gimmie_project:gimmie:*:*:*:*:*:vbulletin:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.