VYPR
Critical severity9.1NVD Advisory· Published Jan 31, 2025· Updated Jun 17, 2026

CVE-2024-57587

CVE-2024-57587

Description

Multiple SQL injection vulnerabilities in EasyVirt DCScope <= 8.6.0 and CO2Scope <= 1.3.0 allows remote unauthenticated attackers to execute arbitrary SQL commands via the (1) username or (2) password parameter to /api/auth/login.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

5
  • EasyVirt/CO2Scope2 versions
    cpe:2.3:a:easyvirt:co2scope:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:easyvirt:co2scope:*:*:*:*:*:*:*:*range: <=1.3.0
    • (no CPE)range: <=1.3.0
  • EasyVirt/DCScope3 versions
    cpe:2.3:a:easyvirt:dcscope:*:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:easyvirt:dcscope:*:*:*:*:*:*:*:*range: <=8.6.0
    • (no CPE)
    • (no CPE)range: <=8.6.0

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.