PT-2025-12676 · Apache · Apache Vcl

Published

2025-03-24

·

Updated

2025-03-27

·

CVE-2024-53678

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Apache VCL versions 2.2 through 2.5.1
Description The issue is related to an SQL Injection vulnerability, where users can modify form data to alter a SELECT SQL statement. However, the data returned by the SELECT statement is not viewable by the attacker.
Recommendations For Apache VCL versions 2.2 through 2.5.1, upgrade to version 2.5.2 to fix the issue.

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-53678

Affected Products

Apache Vcl