CVE-2024-8503

CVSS V2 None CVSS V3 None
Description
An unauthenticated attacker can leverage a time-based SQL injection vulnerability in VICIdial to enumerate database records. By default, VICIdial stores plaintext credentials within the database.
Overview
  • CVE ID
  • CVE-2024-8503
  • Assigner
  • KoreLogic
  • Vulnerability Status
  • PUBLISHED
  • Published Version
  • 2024-09-10T19:22:40.111Z
  • Last Modified Date
  • 2024-09-10T21:02:45.121Z
References
History
Created Old Value New Value Data Type Notes
2024-09-11 13:07:20 Added to TrackCVE