๐Ÿ” CVE Alert

CVE-2025-34099

UNKNOWN 0.0

VICIdial vicidial_sales_viewer.php Unauthenticated Command Injection via Basic Auth Password

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

An unauthenticated command injection vulnerability exists in VICIdial versions 2.9 RC1 through 2.13 RC1, within the vicidial_sales_viewer.php component when password encryption is enabled (a non-default configuration). The application improperly passes the HTTP Basic Authentication password directly to a call to exec() without adequate sanitation. This allows remote attackers to inject and execute arbitrary operating system commands as the web server user. NOTE: This vulnerability was mitigated in 2017.

CWE CWE-78 CWE-20
Vendor vicidial group
Product vicidial
Published Jul 10, 2025
Last Updated Apr 7, 2026
Stay Ahead of the Next One

Get instant alerts for vicidial group vicidial

Be the first to know when new unknown vulnerabilities affecting vicidial group vicidial are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

VICIdial Group / VICIdial
2.9 RC1 โ‰ค 2.13 RC1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
raw.githubusercontent.com: https://raw.githubusercontent.com/rapid7/metasploit-framework/master/modules/exploits/unix/webapp/vicidial_user_authorization_unauth_cmd_exec.rb vulncheck.com: https://vulncheck.com/advisories/vicidial-unauth-command-injection exploit-db.com: https://www.exploit-db.com/exploits/42370 vicidial.org: https://www.vicidial.org/VICIDIALmantis/view.php?id=1016

Credits

bcoles