VICIdial是VICIdial公司的一个软件套件。旨在与 Asterisk 开源 Pbx 电话系统交互,作为一个完整的呼入/呼出联络中心套件,同时支持呼入电子邮件。 VICIdial 2.14b0.5 之前的版本存在SQL注入漏洞,该漏洞源于 /vicidial/AST_agent_time_sheet.php 接口存在问题,攻击者利用该漏洞可能进行欺骗身份、篡改现有数据、泄露系统上的所有数据、破坏数据等。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2022-34879 | 6.5 MEDIUM | VICIDial 2.14b0.5 SVN 3550 was discovered to contain multiple Cross Site Scripting (XSS) v |
| CVE-2022-34876 | 5.5 MEDIUM | VICIDial 2.14b0.5 SVN 3550 was discovered to contain multiple SQL injection vulnerability |
| CVE-2022-34878 | 5.5 MEDIUM | VICIDial 2.14b0.5 SVN 3550 was discovered to contain a SQL injection vulnerability at /vic |
No comments yet