CVE-2022-34878 is a high-severity SQL Injection vulnerability affecting VICIdial's user_stats.php interface, specifically through the file_download parameter. This flaw allows authenticated attackers to fully compromise the database, leading to data disclosure, modification, destruction, and potential administrative control over the database server. With a CVSS score of 8.8 (High) and an EPSS score indicating a higher likelihood of exploitation compared to most CVEs, the risk is significant. While not actively exploited in the wild or on the KEV catalog, a Metasploit module exists, and its high FAUCET Risk Score of 98/100 underscores its exploitability, despite minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.14b0.5CPE matchmatch criteria | cpe:2.3:a:vicidial:vicidial:2.14b0.5:3555:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.