Apache Software Foundation Apache Vcl vulnerabilities
2 known vulnerabilities affecting apache_software_foundation/apache_vcl.
Total CVEs
2
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH1MEDIUM1
Vulnerabilities
Page 1 of 1
CVE-2024-53679HIGHCVSS 8.4≥ 2.1, ≤ 2.5.12025-03-25
CVE-2024-53679 [HIGH] CWE-79 CVE-2024-53679: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache VCL in the User Lookup form. A user with sufficient rights to be able to view this part of the site can craft a URL or be tricked in to clicking a URL that will give a specified user elevated rights.
This issue affects all versions of Apache V
cvelistv5nvd
CVE-2024-53678MEDIUMCVSS 5.1≥ 2.2, ≤ 2.5.12025-03-25
CVE-2024-53678 [MEDIUM] CWE-89 CVE-2024-53678: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability i
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache VCL. Users can modify form data submitted when requesting a new Block Allocation such that a SELECT SQL statement is modified. The data returned by the SELECT statement is not viewable by the attacker.
This issue affects all versions of Apach
cvelistv5nvd