peter bassill · operator
$ cve CVE-2015-2863 JSON

CVE-2015-2863 EXPLOIT

4.3
MEDIUM · CVSS 2.0 · EPSS 10.3% (pctl 96)

Patch early

A public exploit exists.

Description

Open redirect vulnerability in Kaseya Virtual System Administrator (VSA) 7.x before 7.0.0.29, 8.x before 8.0.0.18, 9.0 before 9.0.0.14, and 9.1 before 9.1.0.4 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.

Scoring

CVSS4.3 (MEDIUM, v2.0)
VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
EPSS10.32% — more likely to be exploited than 96% of all CVEs
On CISA KEVno
Public exploityes
Published2015-07-20
Last modified2026-06-17

Affected (1)

VendorProduct
kaseyavirtual system administrator

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD