vsa vulnerabilities
CVEs whose affected-version data names the vsa package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2021-30120Critical· 9.9⚠ ExploitedKaseya VSA before 9.5.7 allows attackers to bypass the 2FA requirement
Kaseya VSA before 9.5.7 allows attackers to bypass the 2FA requirement. The need to use 2FA for authentication in enforce client-side instead of server-side and can be bypassed using a local proxy. Thus rendering 2FA useless. Detailed de…
▾ Abyssalkaseya · vsaEPSS 5.7%via NVD
CVE-2021-30119Medium· 5.4⚠ ExploitedAuthenticated reflective XSS in HelpDeskTab/rcResults.asp The parameter result of /HelpDeskTab/rcResults.asp is insecurely returned in the requested web page and can be used to perform a Cross Site Scripting attack Example request: `http…
Authenticated reflective XSS in HelpDeskTab/rcResults.asp The parameter result of /HelpDeskTab/rcResults.asp is insecurely returned in the requested web page and can be used to perform a Cross Site Scripting attack Example request: `http…
▾ Twilightkaseya · vsaEPSS 50%via NVD