Improper Input Validation in Apache VCL Web GUI and XMLRPC API
CVE-2013-0267
8.8HIGH
What is CVE-2013-0267?
The web GUI and XMLRPC API of Apache VCL prior to version 2.3.2 have vulnerabilities that allow remote authenticated users with specific permissions (nodeAdmin, manageGroup, resourceGrant, or userGrant) to exploit improper input validation. This can lead to privilege escalation, potentially granting unauthorized access, causing a denial of service, or enabling cross-site scripting (XSS) attacks.