An unauthenticated attacker can leverage a time-based SQL injection vulnerability in VICIdial version 2.14-917a to enumerate database records. By default, VICIdial stores plaintext credentials within the database.
🛡️ VERIFIED CYBER INTELLIGENCE ID: #2299933
💾 VICIdial 2.14-917a SQL Injection
⏱️ vor 685d 20h (11.09.2024 um 17:22 Uhr) 📂 💾 IT Security Tools 📡 Feed 🔗 Quelle: packetstormsecurity.com