EasyVirt DCScope and CO2Scope SQL Injection Vulnerability
Vulnerability
A vulnerability allowing SQL injection has been identified in EasyVirt DCScope versions through 8.6.0 and CO2Scope versions through 1.3.0. This vulnerability allows remote unauthenticated attackers to execute arbitrary SQL commands by manipulating the username or password parameters in the login API.
Impact
Exploitation of this vulnerability could lead to unauthorized database access, allowing attackers to dump the entire database and access sensitive information such as user credentials and personal data.
Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM
Vulnerability Rating
Custom Algorithm
spread
0.0impact
2.5exploitability
8.7remediation
0.0relevance
0.0threat
6.4urgency
2.9incentive
5.8Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
