CVE-2021-30119 | Authenticated Authenticated reflective XSS in Kaseya VSA <= v9.5.6
Exp
Authenticated reflective XSS in HelpDeskTab/rcResults.asp The parameter result of /HelpDeskTab/rcResults.asp is insecurely returned in the requested web page and can be used to perform a Cross Site Scripting attack Example request: `https://x.x.x.x/HelpDeskTab/rcResults.asp?result=<script>alert(document.cookie)</script>` The same is true for the parameter FileName of /done.asp Eaxmple request: `https://x.x.x.x/done.asp?FileName=";</script><script>alert(1);a="&PathData=&originalName=shell.aspx&FileSize=4388&TimeElapsed=00:00:00.078`
Conclusion & alert: CVE-2021-30119 is rated High Exploit Risk (75.7/100): CVSS Medium severity, with high exploitation likelihood (EPSS 22.28%, 97th percentile).Core evidence: 1 public exploit reference(s) are indexed (Exploit-DB). EPSS rose +22.09% over the last day, indicating growing attacker interest.Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
Public exploit references (Exploit-DB) for CVE-2021-30119
Exploit prediction scoring system (EPSS) score for CVE-2021-30119
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).