CVE-2024-57587

Multiple SQL injection vulnerabilities in EasyVirt DCScope <= 8.6.0 and CO2Scope <= 1.3.0 allows remote unauthenticated attackers to execute arbitrary SQL commands via the (1) username or (2) password parameter to /api/auth/login.
References
Link Resource
https://github.com/Elymaro/CVE/blob/main/EasyVirt/CVE-2024-57587.md Exploit Third Party Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:easyvirt:co2scope:*:*:*:*:*:*:*:*
cpe:2.3:a:easyvirt:dcscope:*:*:*:*:*:*:*:*

History

24 May 2025, 01:19

Type Values Removed Values Added
References () https://github.com/Elymaro/CVE/blob/main/EasyVirt/CVE-2024-57587.md - () https://github.com/Elymaro/CVE/blob/main/EasyVirt/CVE-2024-57587.md - Exploit, Third Party Advisory
First Time Easyvirt
Easyvirt dcscope
Easyvirt co2scope
CPE cpe:2.3:a:easyvirt:co2scope:*:*:*:*:*:*:*:*
cpe:2.3:a:easyvirt:dcscope:*:*:*:*:*:*:*:*

03 Apr 2025, 14:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 7.5
v2 : unknown
v3 : 9.1

07 Feb 2025, 17:15

Type Values Removed Values Added
Summary (en) EasyVirt DCScope 8.6.0 and earlier and co2Scope 1.3.0 and earlier are vulnerable to SQL Injection on the authentication portal. (en) Multiple SQL injection vulnerabilities in EasyVirt DCScope <= 8.6.0 and CO2Scope <= 1.3.0 allows remote unauthenticated attackers to execute arbitrary SQL commands via the (1) username or (2) password parameter to /api/auth/login.

03 Feb 2025, 18:15

Type Values Removed Values Added
CWE CWE-89
Summary
  • (es) EasyVirt DCScope 8.6.0 y versiones anteriores y co2Scope 1.3.0 y versiones anteriores son vulnerables a la inyección SQL en el portal de autenticación.
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5

31 Jan 2025, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-01-31 22:15

Updated : 2025-05-24 01:19


NVD link : CVE-2024-57587

Mitre link : CVE-2024-57587

CVE.ORG link : CVE-2024-57587


JSON object : View

Products Affected

easyvirt

  • dcscope
  • co2scope
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')