VICIdial Unauthenticated SQL Injection
100Vexday Risk Score
Patch now. It exploitation observed by VulnCheck and has a working public exploit.
ssvc Actcvss 9.8epss 80%
from disclosure to weapon4 days
Published on NVDSep 10
1st PoC+4d
metasploitSep 10
VulnCheck+190d
exploitation probability
80%top 1% of all CVEs
observed exploitation
yesVulnCheck
3 public exploit(s)
An unauthenticated attacker can leverage a time-based SQL injection vulnerability in VICIdial to enumerate database records. By default, VICIdial stores plaintext credentials within the database.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
VICIdial · VICIdialpublic PoCs found — 3
githubgithub.com/Machine-farmer/vicidial-cve-2024-8503-blind-sqli-poc★ 0vulncheckvulncheck.com/xdb/38fdf14467ebunverifiedvulncheckvulncheck.com/xdb/f71c489a4245unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.