CVE-2024-53678

CWE-89SQL Injection3 documents3 sources
Severity
5.1MEDIUM
EPSS
0.1%
top 75.13%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 25

Description

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache VCL. Users can modify form data submitted when requesting a new Block Allocation such that a SELECT SQL statement is modified. The data returned by the SELECT statement is not viewable by the attacker. This issue affects all versions of Apache VCL from 2.2 through 2.5.1. Users are recommended to upgrade to version 2.5.2, which fixes the issue.

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N

Affected Packages2 packages

NVDapache/vcl2.22.5.2
CVEListV5apache_software_foundation/apache_vcl2.22.5.1

🔴Vulnerability Details

2
GHSA
GHSA-fwrx-wppx-25wm: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache VCL2025-03-25
CVEList
Apache VCL: SQL injection vulnerability in New Block Allocation form2025-03-25
CVE-2024-53678 (MEDIUM CVSS 5.1) | Improper Neutralization of Special | cvebase.io