CVE-2024-53354
CVSS 3.1 Score 6.5 of 10 (medium)
Details
Published Jan 31, 2025
Updated: Feb 7, 2025
CWE ID 89
Summary
CVE-2024-53354 refers to multiple SQL injection vulnerabilities identified in EasyVirt DCScope version 8.6.0 and CO2Scope version 1.3.0. These vulnerabilities enable remote, authenticated attackers to execute arbitrary SQL commands. This can be achieved through various parameters, including user parameters in several API endpoints such as /api/management/findfilterlist and /api/audit/findmetawatcher, as well as other parameters like filter, login, and role. Successful exploitation of these vulnerabilities could result in unauthorized access or data breaches.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share