← Back to browse · API

CVE-2024-8504

Severity
HIGH
CVSS
8.8
EPSS
0.76217
Risk score
61.88
CISA KEV
No
PoC
No
Published
2024-09-10
Modified
2025-11-04
First seen
2026-08-07
Aliases
EUVD-2024-49225, GHSA-R47M-G4VH-PXF6
Products
VICIdial Group:VICIdial 2.14-917a
Sources
euvd EUVD-2024-49225

Description

An attacker with authenticated access to VICIdial as an "agent" can execute arbitrary shell commands as the "root" user. This attack can be chained with CVE-2024-8503 to execute arbitrary shell commands starting from an unauthenticated perspective.

References