← Vulnerability feed

Vulnerability record · CVE-2021-30119 · published 9 July 2021

CVE-2021-30119: Kaseya VSA HelpDeskTab rcResults.asp reflected XSS

Kaseya · Vsa

Kaseya VSA reflects the 'result' parameter of /HelpDeskTab/rcResults.asp and the 'FileName' parameter of /done.asp back into the response without proper encoding, allowing reflected cross-site scripting. An authenticated user who is tricked into following a crafted link can have script executed in their VSA session context. The flaw is rated medium severity (CVSS 3.1 5.4) and affects the VSA product per the record.

5.4 CVSS 3.1 Medium EPSS 50% · top 1.1% CWE-79 · Cross-site scripting
5.4CVSS 3.1 base score, v2 3.5
50%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References, 2 tagged exploit
14 Aug 2026Last modified by NVD

Description

Authenticated reflective XSS in HelpDeskTab/rcResults.asp The parameter result of /HelpDeskTab/rcResults.asp is insecurely returned in the requested web page and can be used to perform a Cross Site Scripting attack Example request: `https://x.x.x.x/HelpDeskTab/rcResults.asp?result=<script>alert(document.cookie)</script>` The same is true for the parameter FileName of /done.asp Eaxmple request: `https://x.x.x.x/done.asp?FileName=";</script><script>alert(1);a="&PathData=&originalName=shell.aspx&FileSize=4388&TimeElapsed=00:00:00.078`

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: high.

medium priorityMedium CVSS severity and required authentication plus user interaction limit impact, though high EPSS and public exploit references raise the likelihood of attempts.

What it is

Kaseya VSA reflects the 'result' parameter of /HelpDeskTab/rcResults.asp and the 'FileName' parameter of /done.asp back into the response without proper encoding, allowing reflected cross-site scripting. An authenticated user who is tricked into following a crafted link can have script executed in their VSA session context. The flaw is rated medium severity (CVSS 3.1 5.4) and affects the VSA product per the record.

Impact

An attacker can execute arbitrary script in the victim's authenticated VSA session, potentially stealing session cookies or performing actions as that user. The scope change in the CVSS vector indicates the injected script can affect resources beyond the vulnerable component.

Attack surface

Reached over the network via crafted URLs to /HelpDeskTab/rcResults.asp or /done.asp; the CVSS vector requires low privileges (PR:L) and user interaction (UI:R), so the attacker needs a valid low-privileged account and must lure a victim into clicking a link.

Exploitation

Not listed in CISA KEV and no ransomware usage documented; EPSS is high (0.52687, 98.9th percentile) and DIVD references are tagged Exploit, indicating public proof-of-concept material exists.

What to do

  • Apply the vendor patch referenced by the DIVD advisory (DIVD-2021-00011) as the first action.
  • Encode or validate the 'result' and 'FileName' parameters server-side so reflected input cannot execute as script.
  • Deploy a WAF rule blocking script payloads in requests to /HelpDeskTab/rcResults.asp and /done.asp.
  • Restrict VSA access to trusted networks and enforce least privilege on accounts that can reach these endpoints.
  • Set session cookies HttpOnly and SameSite to limit cookie theft via XSS.

Detection

  • Search web logs for requests to /HelpDeskTab/rcResults.asp or /done.asp containing script tags, event handlers, or encoded equivalents in the result or FileName parameters.
  • Alert on outbound or unusual script content in responses from these endpoints.
  • Monitor for anomalous authenticated sessions or cookie reuse following visits to crafted links.
  • Review VSA audit logs for unexpected actions taken by low-privileged accounts shortly after suspicious URL access.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://csirt.divd.nl/2021/07/07/Kaseya-Limited-Disclosure/ PatchThird Party Advisory
https://csirt.divd.nl/CVE-2021-30119 ExploitThird Party Advisory
https://csirt.divd.nl/DIVD-2021-00011 PatchThird Party Advisory
https://csirt.divd.nl/2021/07/07/Kaseya-Limited-Disclosure/ PatchThird Party Advisory
https://csirt.divd.nl/CVE-2021-30119 ExploitThird Party Advisory
https://csirt.divd.nl/DIVD-2021-00011 PatchThird Party Advisory

Track CVE-2021-30119 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2021-30118Kaseya VSA unauthenticated arbitrary file upload leading to RCEKaseya VSA Unified RMM 9.5.4.2149 exposes /SystemTab/uploader.aspx, which accepts file uploads without validating the sessionId cookie, so any numeri…EPSS 60%analysed8.8CVE-2021-30117Kaseya VSA exportFldr.asp SQL injection via fldrIdThe /InstallTab/exportFldr.asp endpoint in Kaseya VSA is vulnerable to boolean-based blind SQL injection through the fldrId parameter. The flaw is de…EPSS 72%analysed7.5CVE-2021-30120Kaseya vsa vulnerabilityKaseya VSA before 9.5.7 allows attackers to bypass the 2FA requirement. The need to use 2FA for authentication in enforce client-side instead of serv…EPSS 5.7%7.5CVE-2021-30201Kaseya vsa xml external entity (xxe) vulnerabilityThe API /vsaWS/KaseyaWS.asmx can be used to submit XML to the system. When this XML is processed (external) entities are insecurely processed and fet…EPSS 25%6.7CVE-2019-14510Kaseya vsa incorrect default permissions vulnerabilityAn issue was discovered in Kaseya VSA RMM through 9.5.0.22. When using the default configuration, the LAN Cache feature creates a local account FSAdm…EPSS 0.53%6.5CVE-2021-30121Kaseya vsa inclusion from untrusted sphere vulnerabilitySemi-authenticated local file inclusion The contents of arbitrary files can be returned by the webserver Example request: `https://x.x.x.x/KLC/js/Kas…EPSS 4.8%6.1CVE-2026-42897Microsoft Exchange Server XSS enables spoofingMicrosoft Exchange Server and Exchange Server Subscription Edition fail to neutralize input during web page generation, a cross-site scripting flaw (…KEVEPSS 0.52%analysed6.1CVE-2025-48700Zimbra Classic UI stored XSS via crafted email HTMLZimbra Collaboration Suite Classic UI fails to properly sanitize HTML content in email messages, allowing crafted tag structures and attribute values…KEVEPSS 1.7%analysed

Source: NIST National Vulnerability Database (record CVE-2021-30119), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.