Описание
Semi-authenticated local file inclusion The contents of arbitrary files can be returned by the webserver Example request: https://x.x.x.x/KLC/js/Kaseya.SB.JS/js.aspx?path=C:\Kaseya\WebPages\dl.asp A valid sessionId is required but can be easily obtained via CVE-2021-30118
Ссылки
- PatchThird Party Advisory
- ExploitThird Party Advisory
- PatchThird Party Advisory
- PatchThird Party Advisory
- ExploitThird Party Advisory
- PatchThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 9.5.6 (исключая)
cpe:2.3:a:kaseya:vsa:*:*:*:*:-:*:*:*
EPSS
Процентиль: 62%
0.00426
Низкий
6.5 Medium
CVSS3
4 Medium
CVSS2
Дефекты
CWE-829
Связанные уязвимости
CVSS3: 8.8
github
больше 3 лет назад
Local file inclusion exists in Kaseya VSA before 9.5.6.
EPSS
Процентиль: 62%
0.00426
Низкий
6.5 Medium
CVSS3
4 Medium
CVSS2
Дефекты
CWE-829