Jaggar Henry of KoreLogic, Inc.

1 exploit Active since Sep 2024
CVE-2024-8504 METASPLOIT HIGH ruby WORKING POC
VICIdial Agent Interface - Authenticated Root Command Execution
An attacker with authenticated access to VICIdial as an "agent" can execute arbitrary shell commands as the "root" user. This attack can be chained with CVE-2024-8503 to execute arbitrary shell commands starting from an unauthenticated perspective.
CVSS 8.8