CVE-2024-8503

An unauthenticated attacker can leverage a time-based SQL injection vulnerability in VICIdial to enumerate database records. By default, VICIdial stores plaintext credentials within the database.
Configurations

No configuration.

History

11 Sep 2024, 16:26

Type Values Removed Values Added
Summary
  • (es) Un atacante no autenticado puede aprovechar una vulnerabilidad de inyección SQL basada en tiempo en VICIdial para enumerar registros de la base de datos. De manera predeterminada, VICIdial almacena credenciales de texto plano dentro de la base de datos.

10 Sep 2024, 20:35

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8

10 Sep 2024, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-09-10 20:15

Updated : 2024-09-11 16:26


NVD link : CVE-2024-8503

Mitre link : CVE-2024-8503

CVE.ORG link : CVE-2024-8503


JSON object : View

Products Affected

No product.

CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')