CVE-2024-57587
- EPSS 0.25%
- Veröffentlicht 31.01.2025 22:15:13
- Zuletzt bearbeitet 24.05.2025 01:19:45
Multiple SQL injection vulnerabilities in EasyVirt DCScope <= 8.6.0 and CO2Scope <= 1.3.0 allows remote unauthenticated attackers to execute arbitrary SQL commands via the (1) username or (2) password parameter to /api/auth/login.
CVE-2024-55062
- EPSS 5.43%
- Veröffentlicht 31.01.2025 22:15:10
- Zuletzt bearbeitet 24.05.2025 01:18:38
Code Injection vulnerability in EasyVirt DCScope <= 8.6.0 and CO2Scope <= 1.3.0 allows remote unauthenticated attackers to execute arbitrary code to /api/license/sendlicense/.
CVE-2024-53354
- EPSS 0.13%
- Veröffentlicht 31.01.2025 22:15:09
- Zuletzt bearbeitet 23.05.2025 15:39:19
Multiple SQL injection vulnerabilities in EasyVirt DCScope <= 8.6.0 and CO2Scope <= 1.3.0 allows remote authenticated attackers to execute arbitrary SQL commands via the (1) user parameter to /api/management/findfilterlist; the (2) user or (3) filter...
CVE-2024-53355
- EPSS 0.42%
- Veröffentlicht 31.01.2025 22:15:09
- Zuletzt bearbeitet 23.05.2025 15:37:53
Multiple incorrect access control issues in EasyVirt DCScope <= 8.6.0 and CO2Scope <= 1.3.0 allows remote authenticated attackers, with low privileges, to (1) add an admin user via the /api/user/addalias route; (2) modifiy a user via the /api/user/up...
CVE-2024-53356
- EPSS 0.49%
- Veröffentlicht 31.01.2025 22:15:09
- Zuletzt bearbeitet 23.05.2025 15:37:29
Weak JWT Secret vulnerabilitiy in EasyVirt DCScope <= 8.6.0 and CO2Scope <= 1.3.0 allows remote attackers to generate JWT for privilege escalation. The HMAC secret used for generating tokens is hardcoded as "somerandomaccesstoken". A weak HMAC secret...
CVE-2024-53357
- EPSS 0.17%
- Veröffentlicht 31.01.2025 22:15:09
- Zuletzt bearbeitet 24.05.2025 01:15:54
Multiple SQL injection vulnerabilities in EasyVirt DCScope <= 8.6.0 and CO2Scope <= 1.3.0 allows remote authenticated attackers, with low privileges, to (1) add an admin user via the /api/user/addalias route; (2) modifiy a user via the /api/user/upda...