PT-2024-39060 · Vicidial · Vicidial

Jaggar Henry

·

Published

2024-07-05

·

Updated

2025-11-21

·

CVE-2024-8503

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions VICIdial versions prior to 2.14-917a VICIdial version 2.14-917a
Description An unauthenticated attacker can exploit a time-based SQL injection flaw in VICIdial to retrieve database records. The software, by default, stores credentials in plaintext within the database. An authenticated attacker with agent access can execute arbitrary shell commands as the root user. This root access can be chained with the SQL injection issue to further compromise the system. The vulnerability resides in the VERM AJAX functions.php script due to a lack of protection against SQL injection attacks.
Recommendations VICIdial versions prior to 2.14-917a: Update to version 2.14-917a or later. VICIdial version 2.14-917a: Apply any available updates or patches to address the remote code execution issue.

Exploit

Fix

SQL injection

Weakness Enumeration

Related Identifiers

BDU:2025-02024
CVE-2024-8503

Affected Products

Vicidial