CVE-2024-8503 is an unauthenticated SQL injection vulnerability in VICIdial. The flaw allows a remote attacker to inject SQL statements into a vulnerable application component without prior authentication and use time-based techniques to enumerate and extract database records. In affected deployments, this exposure is especially severe because VICIdial stores plaintext credentials in the backend database by default, enabling the SQL injection to be used to recover administrative credentials. The vulnerability can serve as the initial stage of a broader compromise chain by providing access to sensitive application data and privileged account material.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a small standalone Python proof-of-concept for CVE-2024-8503 affecting VICIdial. It contains one substantive code file (CVE-2024-8503-POC.py), a README, and a license. The script is not part of a larger exploit framework. The exploit targets an unauthenticated SQL injection in VICIdial's /VERM/VERM_AJAX_functions.php endpoint. According to the README and embedded comments, the injection point is a crafted HTTP Basic Auth username value. The tool implements a time-based blind SQLi engine that infers data through response timing rather than direct output. It is designed as a read-only extractor rather than an RCE or shell-dropping exploit. Core capabilities include: vulnerability confirmation, extraction of database metadata (version, database name, current user, hostname, privileges, table count), table enumeration, column enumeration, limited row extraction, auto-extraction of a chosen table, SELECT-only custom query execution, resumable scans via on-disk JSON state, and CSV/JSON export. The code enforces strict PoC limits: max 10 tables, 10 columns per table, 10 rows per table, 100 characters per cell, and 250 characters for metadata. These limits support the claim that the tool is intended for controlled demonstration. Repository structure is straightforward: the Python script is the entry point and contains configuration constants, metadata queries, state management, CLI handling, and extraction workflow. The README documents usage patterns including self-check mode, interactive mode, full scan mode, and examples against a placeholder target URL. The script stores progress in .vicidial_scan_state.json and explicitly ignores a legacy pickle state file for safety. Overall, this is a real exploit PoC for unauthenticated web-based blind SQL injection against VICIdial, with operational extraction functionality but no post-exploitation payload beyond database data retrieval.
This repository contains a single Metasploit auxiliary module (modules/auxiliary/scanner/http/vicidial_sql_enum_users_pass.rb) that exploits a time-based blind SQL injection vulnerability (CVE-2024-8503) in VICIdial. The module targets the /VERM/VERM_AJAX_functions.php endpoint, using crafted HTTP requests with a malicious Authorization header to trigger the SQL injection. Upon successful exploitation, the module enumerates and dumps admin credentials (usernames and passwords) from the 'vicidial_users' table in the VICIdial database. The exploit is operational and leverages Metasploit's SQLi mixin for automated extraction. The code is written in Ruby and is designed to be run within the Metasploit framework. No hardcoded IPs or domains are present; the target is specified by the user at runtime.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A SQL injection vulnerability in VICIdial, referenced as a Metasploit module PR.
A critical vulnerability in Vicidial Contact Center Suite.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.