CVE-2024-55063: Easyvirt DC Netscope
High severity, CVSS 8.8. EPSS: 1.1% chance of exploitation in the next 30 days.
Multiple Code Injection vulnerabilities in EasyVirt DC NetScope <= 8.7.0 allows remote authenticated attackers to execute arbitrary code via the (1) lang parameter to /international/keyboard/options; the (2) keyboard_layout or (3) keyboard_variant parameter to /international/settings/keyboard; the (4) timezone parameter to /international/settings/timezone.
Affected products
- Easyvirt DC Netscope: up to and including 8.7.0
Published 2025-05-19. Last modified 2026-06-17.