cve/2024/CVE-2024-8503.md
2025-09-29 21:09:30 +02:00

1016 B

CVE-2024-8503

Description

An unauthenticated attacker can leverage a time-based SQL injection vulnerability in VICIdial to enumerate database records. By default, VICIdial stores plaintext credentials within the database.

POC

Reference

Github