Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-53974 | Multiple cross-site scripting (XSS) vulnerabilities in EasyVirt DC NetScope <= 8.6.4 allow remote attackers to inject arbitrary JavaScript or HTML code via the (1) smtp_server, (2) smtp_account, (3) smtp_password, or (4) email_recipients parameter to /smtp/update; the (5) ntp or (6) dns parameter to /proxy/ntp/change; the (7) newVcenterAddress parameter to /process_new_vcenter. |
Tue, 04 Mar 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-79 | |
| Metrics |
cvssV3_1
|
Mon, 03 Mar 2025 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Multiple cross-site scripting (XSS) vulnerabilities in EasyVirt DC NetScope <= 8.6.4 allow remote attackers to inject arbitrary JavaScript or HTML code via the (1) smtp_server, (2) smtp_account, (3) smtp_password, or (4) email_recipients parameter to /smtp/update; the (5) ntp or (6) dns parameter to /proxy/ntp/change; the (7) newVcenterAddress parameter to /process_new_vcenter. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-03-04T16:46:32.743Z
Reserved: 2024-12-06T00:00:00.000Z
Link: CVE-2024-55064
Updated: 2025-03-04T16:46:26.944Z
Status : Awaiting Analysis
Published: 2025-03-03T22:15:36.700
Modified: 2025-03-04T17:15:13.390
Link: CVE-2024-55064
No data.
OpenCVE Enrichment
Updated: 2025-07-12T22:01:04Z
EUVD