← Back to browse · API

CVE-2024-8503

Severity
CRITICAL
CVSS
9.8
EPSS
0.8023
Risk score
67.28
CISA KEV
No
PoC
No
Published
2024-09-10
Modified
2025-11-04
First seen
2026-08-07
Aliases
EUVD-2024-49224, GHSA-5QF6-WQM9-P35X
Products
VICIdial Group:VICIdial 2.14-917a
Sources
euvd EUVD-2024-49224

Description

An unauthenticated attacker can leverage a time-based SQL injection vulnerability in VICIdial to enumerate database records. By default, VICIdial stores plaintext credentials within the database.

References