Easyvirt

Dcscope

6 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.25%
  • Veröffentlicht 31.01.2025 22:15:13
  • Zuletzt bearbeitet 24.05.2025 01:19:45

Multiple SQL injection vulnerabilities in EasyVirt DCScope <= 8.6.0 and CO2Scope <= 1.3.0 allows remote unauthenticated attackers to execute arbitrary SQL commands via the (1) username or (2) password parameter to /api/auth/login.

Exploit
  • EPSS 5.43%
  • Veröffentlicht 31.01.2025 22:15:10
  • Zuletzt bearbeitet 24.05.2025 01:18:38

Code Injection vulnerability in EasyVirt DCScope <= 8.6.0 and CO2Scope <= 1.3.0 allows remote unauthenticated attackers to execute arbitrary code to /api/license/sendlicense/.

Exploit
  • EPSS 0.13%
  • Veröffentlicht 31.01.2025 22:15:09
  • Zuletzt bearbeitet 23.05.2025 15:39:19

Multiple SQL injection vulnerabilities in EasyVirt DCScope <= 8.6.0 and CO2Scope <= 1.3.0 allows remote authenticated attackers to execute arbitrary SQL commands via the (1) user parameter to /api/management/findfilterlist; the (2) user or (3) filter...

Exploit
  • EPSS 0.42%
  • Veröffentlicht 31.01.2025 22:15:09
  • Zuletzt bearbeitet 23.05.2025 15:37:53

Multiple incorrect access control issues in EasyVirt DCScope <= 8.6.0 and CO2Scope <= 1.3.0 allows remote authenticated attackers, with low privileges, to (1) add an admin user via the /api/user/addalias route; (2) modifiy a user via the /api/user/up...

Exploit
  • EPSS 0.49%
  • Veröffentlicht 31.01.2025 22:15:09
  • Zuletzt bearbeitet 23.05.2025 15:37:29

Weak JWT Secret vulnerabilitiy in EasyVirt DCScope <= 8.6.0 and CO2Scope <= 1.3.0 allows remote attackers to generate JWT for privilege escalation. The HMAC secret used for generating tokens is hardcoded as "somerandomaccesstoken". A weak HMAC secret...

Exploit
  • EPSS 0.17%
  • Veröffentlicht 31.01.2025 22:15:09
  • Zuletzt bearbeitet 24.05.2025 01:15:54

Multiple SQL injection vulnerabilities in EasyVirt DCScope <= 8.6.0 and CO2Scope <= 1.3.0 allows remote authenticated attackers, with low privileges, to (1) add an admin user via the /api/user/addalias route; (2) modifiy a user via the /api/user/upda...