CVE-2024-53357
Multiple SQL injection vulnerabilities in EasyVirt DCScope <= 8.6.0 and CO2Scope <= 1.3.0 allows remote authenticated attackers, with low privileges, to (1) add an admin user via the /api/user/addalias route.
(2) modifiy a user via the /api/user/updatealiasroute.
(4) delete users via the /api/user/delalias route.
(4) get users via the /api/user/aliases route.
(5) add a root group via the /api/user/adduserroute.
(6) modifiy a group via the /api/user/updateuser route.
(7) delete a group via the /api/user/deluser route.
(8) get groups via the /api/user/usersroute.
(9) add an admin role via the /api/user/addrole route.
(10) modifiy a role via the /api/user/updaterole route.
(11) delete a role via the /api/user/delrole route.
(12) get roles via the /api/user/roles route.
- Public exploit or PoC is available
- SSVC automatable: yes - attacks can be scripted at scale
- CVSS base score ≥ 7.0
ATT&CK techniques
2Techniques this CVE enables - linked via CWECAPECATT&CK. High◆ = named directly in ATT&CK or Nuclei templates.
▤ Build a SIEM detection for these techniquesCAPEC attack patterns
2Attack patterns this CVE enables - the bridge from weakness to ATT&CK technique.