PT-2024-39060 · Vicidial · Vicidial
Jaggar Henry
·
Published
2024-07-05
·
Updated
2025-11-21
·
CVE-2024-8503
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
VICIdial versions prior to 2.14-917a
VICIdial version 2.14-917a
Description
An unauthenticated attacker can exploit a time-based SQL injection flaw in VICIdial to retrieve database records. The software, by default, stores credentials in plaintext within the database. An authenticated attacker with agent access can execute arbitrary shell commands as the root user. This root access can be chained with the SQL injection issue to further compromise the system. The vulnerability resides in the
VERM AJAX functions.php script due to a lack of protection against SQL injection attacks.Recommendations
VICIdial versions prior to 2.14-917a: Update to version 2.14-917a or later.
VICIdial version 2.14-917a: Apply any available updates or patches to address the remote code execution issue.
Exploit
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Vicidial