VICIDial 2.14b0.5 SVN 3550 was discovered to contain multiple Cross Site Scripting (XSS) vulnerabilities at /vicidial/admin.php.
Vulnerability Description
Reflected Cross Site Scripting (XSS) vulnerabilities in AST Agent Time Sheet interface (/vicidial/AST_agent_time_sheet.php) of VICIdial via agent, and search_archived_data parameters. This issue affects: VICIdial 2.14b0.5 versions prior to 3555.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2022-34879
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- h00die for discovery, disclosure, and exploit. Matt Florell with VICIdial for patching the software.
More from VICIdial
View All →Affected Vendor
VICIdial
View all reports →