CVE-2024-8504 is a critical authenticated remote code execution vulnerability in VICIdial. An attacker with valid access to the application as an agent can exploit the flaw to execute arbitrary shell commands on the underlying server with root privileges. Available reporting indicates the exploitation technique involves poisoned recording files, enabling command execution through VICIdial functionality accessible to an authenticated low-privilege user. The issue can also be chained with CVE-2024-8503, an unauthenticated SQL injection vulnerability, to progress from unauthenticated access to credential compromise and then to full server-side command execution.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
3 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a single Metasploit module (vicidial_agent_authenticated_rce.rb) targeting VICIdial, an open-source call center suite. The exploit leverages an authenticated agent session (or can be chained with CVE-2024-8503 for unauthenticated access) to achieve remote code execution as the root user on the underlying system. The module is written in Ruby and follows the standard Metasploit structure, including methods for checking vulnerability, authenticating, escalating privileges, and delivering a payload. The exploit works by manipulating VICIdial's web interface endpoints, creating dummy campaigns and lists, and ultimately inserting a malicious recording that is executed via a cron job. The payload is customizable and typically results in a command shell as root. The module interacts with several HTTP endpoints on the target, including /agc/vicidial.php, /agc/manager_send.php, and /agc/conf_exten_check.php. The exploit is operational and provides a reliable method for attackers with valid credentials (or those able to chain with another vulnerability) to fully compromise vulnerable VICIdial installations.
This repository provides a combined exploit for two critical vulnerabilities in VICIdial: CVE-2024-8503 (unauthenticated SQL injection) and CVE-2024-8504 (authenticated remote code execution). The main exploit script, 'exploit.py', is a Python tool that can operate in two modes: (1) retrieve admin credentials from a vulnerable VICIdial instance via SQL injection, and (2) use those credentials to upload a malicious recording file and achieve remote code execution, typically resulting in a reverse shell to the attacker's server. The script is modular, allowing the user to perform either attack independently. It requires Python 3.10+ and several dependencies (bs4, Faker, urllib3, requests, rich_click). The README provides detailed usage instructions, including required arguments for both SQLi and RCE modes, and emphasizes the need for the attacker to have a server with open ports to receive the reverse shell. The exploit targets the '/VERM/VERM_AJAX_functions.php' endpoint on the VICIdial server for SQLi and leverages authenticated functionality for the RCE. The repository is well-structured, with clear separation between the two exploit stages, and is based on original research by KoreLogic.
This repository is an operational exploit suite targeting ViciDial version 2.14-917a, specifically exploiting CVE-2024-8503 (unauthenticated SQL injection) and CVE-2024-8504 (authenticated remote code execution). The suite is implemented in Python and consists of modular scripts: - `main.py`: The main entry point, providing a menu-driven interface to select between SQLi, RCE, and API modules. - `sqli.py`: Implements a time-based SQL injection attack against `/VERM/VERM_AJAX_functions.php` to extract admin credentials without authentication. It uses timing differences to enumerate usernames and passwords character by character. - `rce.py`: Performs authenticated remote code execution by poisoning the `filename` parameter in requests to `/agc/manager_send.php`, which is later executed by a cron job, allowing arbitrary command execution or reverse shell as root. It can also set up a listener and deliver a payload via a simple web server. - `api.py`: Provides post-exploitation interaction with the ViciDial API, allowing the attacker to list campaigns, retrieve server info, and make calls using the stolen credentials. The repository also includes detailed advisories for both vulnerabilities, a README with usage instructions, and standard project files. The exploit is not part of a larger framework and is self-contained. It is operational, providing both credential extraction and full remote code execution, as well as post-exploitation control via the API. The attack vector is network-based, and all endpoints are customizable by the user at runtime.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An authenticated remote code execution vulnerability in VICIdial, referenced as a Metasploit module PR.
A critical vulnerability in Vicidial Contact Center Suite.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.