EasyVirt DCScope <=8.6.0 and CO2Scope <=1.3.0 are...
Unreviewed
Published
Feb 1, 2025
to the GitHub Advisory Database
•
Updated Feb 1, 2025
Description
Published by the National Vulnerability Database
Jan 31, 2025
Published to the GitHub Advisory Database
Feb 1, 2025
Last updated
Feb 1, 2025
EasyVirt DCScope <=8.6.0 and CO2Scope <=1.3.0 are vulnerable to Incorrect Access Control. This vulnerability allows the api to be used to create/modify/delete information about aliases (users) / users (groups) / roles.
References