PT-2021-18610 · Kaseya · Kaseya Vsa

Frank Breedijk

+2

·

Published

2021-07-09

·

Updated

2022-04-29

·

CVE-2021-30119

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Kaseya VSA versions prior to 9.5.7
Description The issue is related to an authenticated reflective Cross Site Scripting (XSS) attack. Specifically, the result parameter of the /HelpDeskTab/rcResults.asp endpoint and the FileName parameter of the /done.asp endpoint are insecurely returned in the requested web page, allowing for XSS attacks. For example, an attacker could use the endpoint /HelpDeskTab/rcResults.asp with a malicious result parameter, such as <script>alert(document.cookie)</script>, to execute a Cross Site Scripting attack. Similarly, the /done.asp endpoint is vulnerable with a crafted FileName parameter.
Recommendations For versions prior to 9.5.7, update to version 9.5.7 or later to resolve the issue. As a temporary workaround, consider restricting access to the /HelpDeskTab/rcResults.asp and /done.asp endpoints until a patch is applied. Avoid using the result parameter in the /HelpDeskTab/rcResults.asp endpoint and the FileName parameter in the /done.asp endpoint until the issue is resolved.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-30119

Affected Products

Kaseya Vsa