EasyVirt DCScope and CO2Scope SQL Injection Vulnerability
Vulnerability
Multiple SQL injection vulnerabilities have been identified in EasyVirt DCScope versions through 8.6.4 and CO2Scope versions through 1.3.4. These vulnerabilities allow remote authenticated attackers to execute arbitrary SQL commands by manipulating various parameters in specific API endpoints.
Impact
Exploitation of these vulnerabilities allows for arbitrary SQL command execution, which could lead to unauthorized data access or manipulation within the application's database.
Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM
Vulnerability Rating
Custom Algorithm
spread
0.0impact
5.0exploitability
5.2remediation
0.0relevance
0.0threat
0.0urgency
2.9incentive
1.7Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
