RULE(RULE ID:338422)

Rule General Information
Release Date: 2024-09-18
Rule Name: VICIdial 2.14-917a SQL Injection Vulnerability (CVE-2024-8503)
Severity:
CVE ID:
Rule Protection Details
Description: An unauthenticated attacker can leverage a time-based SQL injection vulnerability in VICIdial to enumerate database records. By default, VICIdial stores plaintext credentials within the database.
Impact: An attacker can inject arbitrary sql commands to view or change the database of the target by exploiting the vulnerability successfully.
Affected OS: Windows, Linux, Others
Reference: https://korelogic.com/Resources/Advisories/KL-001-2024-011.txt
https://www.vicidial.org/vicidial.php
Solutions
Refer to the announcement or patch by the vendor: https://www.vicidial.org/vicidial.php