MEDIUM🇵🇱 Wersja polska

CVE-2015-2863

CVSS 4.3v2.0pub. 2015-07-20upd. 2026-05-06

Open redirect vulnerability in Kaseya Virtual System Administrator (VSA) 7.x before 7.0.0.29, 8.x before 8.0.0.18, 9.0 before 9.0.0.14, and 9.1 before 9.1.0.4 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.

CVSS Vector
AV:N/AC:M/Au:N/C:N/I:P/A:N
  • Kaseya Virtual System Administrator

    APP
    Kaseya
    7.0 – 7.0.0.29 (excl.)8.0 – 8.0.0.18 (excl.)9.0 – 9.0.0.14 (excl.)9.1 – 9.1.0.4 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2018-20753CRITICAL9.8⚠ KEVPL ✓same product

Kaseya VSA RMM — zdalne wykonanie PowerShell payload na zarządzanych urządzeniach

CVE-2015-6922CRITICAL9.8PL ✓same product

Kaseya VSA — pominięcie uwierzytelnienia, RCE i dodanie konta admina

CVE-2015-6589HIGH8.8same product

Directory traversal vulnerability in Kaseya Virtual System Administrator (VSA) 7.0.0.0 before 7.0.0.33, 8..0.0...

CVE-2019-15506HIGH7.5same product

An issue was discovered in Kaseya Virtual System Administrator (VSA) through 9.4.0.37. It has a critical infor...

CVE-2017-12410HIGH7.4same product

It is possible to exploit a Time of Check & Time of Use (TOCTOU) vulnerability by winning a race condition whe...