First published: Mon Jul 20 2015(Updated: )
Open redirect vulnerability in Kaseya Virtual System Administrator (VSA) 7.x before 7.0.0.29, 8.x before 8.0.0.18, 9.0 before 9.0.0.14, and 9.1 before 9.1.0.4 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.
Credit: cret@cert.org
Affected Software | Affected Version | How to fix |
---|---|---|
Kaseya VSA Agent | >=7.0<7.0.0.29 | |
Kaseya VSA Agent | >=8.0<8.0.0.18 | |
Kaseya VSA Agent | >=9.0<9.0.0.14 | |
Kaseya VSA Agent | >=9.1<9.1.0.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-2863 is classified as a medium-severity vulnerability due to its potential for phishing attacks.
To fix CVE-2015-2863, update Kaseya Virtual System Administrator to the latest version as specified in the vendor's security updates.
CVE-2015-2863 affects Kaseya VSA versions 7.x prior to 7.0.0.29, 8.x prior to 8.0.0.18, 9.0 prior to 9.0.0.14, and 9.1 prior to 9.1.0.4.
Using CVE-2015-2863, attackers can execute open redirect attacks to redirect users to malicious websites for phishing.
Yes, CVE-2015-2863 is a known vulnerability reported in Kaseya Virtual System Administrator affecting multiple versions.