CVE-2024-53678

Severity CVSS v4.0:
MEDIUM
Type:
CWE-89 SQL Injection
Publication date:
25/03/2025
Last modified:
14/07/2025

Description

Improper Neutralization of Special Elements used in an SQL Command (&amp;#39;SQL Injection&amp;#39;) vulnerability in Apache VCL. Users can modify form data submitted when requesting a new Block Allocation such that a SELECT SQL statement is modified. The data returned by the SELECT statement is not viewable by the attacker.<br /> <br /> This issue affects all versions of Apache VCL from 2.2 through 2.5.1.<br /> <br /> Users are recommended to upgrade to version 2.5.2, which fixes the issue.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:apache:vcl:*:*:*:*:*:*:*:* 2.2 (including) 2.5.2 (excluding)