HIGH🇵🇱 Wersja polska

CVE-2015-6589

CVSS 8.8v3.1pub. 2020-02-13upd. 2024-11-21

Directory traversal vulnerability in Kaseya Virtual System Administrator (VSA) 7.0.0.0 before 7.0.0.33, 8..0.0.0 before 8.0.0.23, 9.0.0.0 before 9.0.0.19, and 9.1.0.0 before 9.1.0.9 allows remote authenticated users to write to and execute arbitrary files due to insufficient restrictions in file paths to json.ashx.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
  • Kaseya Virtual System Administrator

    APP
    Kaseya
    7.0.0.0 – 7.0.0.33 (excl.)8.0.0.0 – 8.0.0.23 (excl.)9.0.0.0 – 9.0.0.19 (excl.)9.1.0.0 – 9.1.0.9 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Path Traversal
CWE
References

Related vulnerabilities

CVE-2018-20753CRITICAL9.8⚠ KEVPL ✓same product

Kaseya VSA RMM — zdalne wykonanie PowerShell payload na zarządzanych urządzeniach

CVE-2015-6922CRITICAL9.8PL ✓same product

Kaseya VSA — pominięcie uwierzytelnienia, RCE i dodanie konta admina

CVE-2019-15506HIGH7.5same product

An issue was discovered in Kaseya Virtual System Administrator (VSA) through 9.4.0.37. It has a critical infor...

CVE-2017-12410HIGH7.4same product

It is possible to exploit a Time of Check & Time of Use (TOCTOU) vulnerability by winning a race condition whe...

CVE-2015-2863MEDIUM4.3same product

Open redirect vulnerability in Kaseya Virtual System Administrator (VSA) 7.x before 7.0.0.29, 8.x before 8.0.0...