VYPR
Medium severity5.4NVD Advisory· Published Mar 25, 2025· Updated Jun 17, 2026

CVE-2024-53679

CVE-2024-53679

Description

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache VCL in the User Lookup form. A user with sufficient rights to be able to view this part of the site can craft a URL or be tricked in to clicking a URL that will give a specified user elevated rights.

This issue affects all versions of Apache VCL through 2.5.1.

Users are recommended to upgrade to version 2.5.2, which fixes the issue.

Affected products

3
  • Apache/Vcl2 versions
    cpe:2.3:a:apache:vcl:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:apache:vcl:*:*:*:*:*:*:*:*range: >=2.1,<2.5.2
    • (no CPE)range: <=2.5.1
  • Apache/Apachecpe-rescue
    Range: 2.1

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.