CVE-2024-57587

Multiple SQL injection vulnerabilities in EasyVirt DCScope <= 8.6.0 and CO2Scope <= 1.3.0 allows remote unauthenticated attackers to execute arbitrary SQL commands via the (1) username or (2) password parameter to /api/auth/login.
References
Link Resource
https://github.com/Elymaro/CVE/blob/main/EasyVirt/CVE-2024-57587.md Exploit Third Party Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:easyvirt:co2scope:*:*:*:*:*:*:*:*
cpe:2.3:a:easyvirt:dcscope:*:*:*:*:*:*:*:*

History

24 May 2025, 01:19

Type Values Removed Values Added
CPE cpe:2.3:a:easyvirt:co2scope:*:*:*:*:*:*:*:*
cpe:2.3:a:easyvirt:dcscope:*:*:*:*:*:*:*:*
First Time Easyvirt co2scope
Easyvirt
Easyvirt dcscope
References () https://github.com/Elymaro/CVE/blob/main/EasyVirt/CVE-2024-57587.md - () https://github.com/Elymaro/CVE/blob/main/EasyVirt/CVE-2024-57587.md - Exploit, Third Party Advisory

03 Apr 2025, 14:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 7.5
v2 : unknown
v3 : 9.1

07 Feb 2025, 17:15

Type Values Removed Values Added
Summary (en) EasyVirt DCScope 8.6.0 and earlier and co2Scope 1.3.0 and earlier are vulnerable to SQL Injection on the authentication portal. (en) Multiple SQL injection vulnerabilities in EasyVirt DCScope <= 8.6.0 and CO2Scope <= 1.3.0 allows remote unauthenticated attackers to execute arbitrary SQL commands via the (1) username or (2) password parameter to /api/auth/login.

03 Feb 2025, 18:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
Summary
  • (es) EasyVirt DCScope 8.6.0 y versiones anteriores y co2Scope 1.3.0 y versiones anteriores son vulnerables a la inyección SQL en el portal de autenticación.
CWE CWE-89

31 Jan 2025, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-01-31 22:15

Updated : 2025-05-24 01:19


NVD link : CVE-2024-57587

Mitre link : CVE-2024-57587

CVE.ORG link : CVE-2024-57587


JSON object : View

Products Affected

easyvirt

  • co2scope
  • dcscope
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')