CVE-2022-34878 | VICIdial User Stats Interface /vicidial/user_stats.php file_download sql injection
A vulnerability classified as critical has been found in VICIdial. Affected is an unknown function of the file /vicidial/user_stats.php of the component User Stats Interface. The manipulation of the argument file_download leads to sql injection.
This vulnerability is traded as CVE-2022-34878. It is possible to launch the attack remotely. Furthermore, there is an exploit available.