CVE-2024-57587

Multiple SQL injection vulnerabilities in EasyVirt DCScope <= 8.6.0 and CO2Scope <= 1.3.0 allows remote unauthenticated attackers to execute arbitrary SQL commands via the (1) username or (2) password parameter to /api/auth/login.
CVSS

No CVSS.

References
Link Resource
https://github.com/Elymaro/CVE/blob/main/EasyVirt/CVE-2024-57587.md Exploit Third Party Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:easyvirt:co2scope:*:*:*:*:*:*:*:*
cpe:2.3:a:easyvirt:dcscope:*:*:*:*:*:*:*:*

History

24 May 2025, 01:19

Type Values Removed Values Added
References () https://github.com/Elymaro/CVE/blob/main/EasyVirt/CVE-2024-57587.md - () https://github.com/Elymaro/CVE/blob/main/EasyVirt/CVE-2024-57587.md - Exploit, Third Party Advisory
CPE cpe:2.3:a:easyvirt:dcscope:*:*:*:*:*:*:*:*
cpe:2.3:a:easyvirt:co2scope:*:*:*:*:*:*:*:*
First Time Easyvirt
Easyvirt dcscope
Easyvirt co2scope

07 Feb 2025, 17:15

Type Values Removed Values Added
Summary EasyVirt DCScope 8.6.0 and earlier and co2Scope 1.3.0 and earlier are vulnerable to SQL Injection on the authentication portal. Multiple SQL injection vulnerabilities in EasyVirt DCScope <= 8.6.0 and CO2Scope <= 1.3.0 allows remote unauthenticated attackers to execute arbitrary SQL commands via the (1) username or (2) password parameter to /api/auth/login.

31 Jan 2025, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-01-31 22:15

Updated : 2025-05-24 01:19


NVD link : CVE-2024-57587

Mitre link : CVE-2024-57587


JSON object : View

Products Affected

easyvirt

  • dcscope
  • co2scope
CWE

No CWE.