Vulnerability record · CVE-2021-30119 · published 9 July 2021
CVE-2021-30119: Kaseya VSA HelpDeskTab rcResults.asp reflected XSS
Kaseya · Vsa
Kaseya VSA reflects the 'result' parameter of /HelpDeskTab/rcResults.asp and the 'FileName' parameter of /done.asp back into the response without proper encoding, allowing reflected cross-site scripting. An authenticated user who is tricked into following a crafted link can have script executed in their VSA session context. The flaw is rated medium severity (CVSS 3.1 5.4) and affects the VSA product per the record.
Description
Authenticated reflective XSS in HelpDeskTab/rcResults.asp The parameter result of /HelpDeskTab/rcResults.asp is insecurely returned in the requested web page and can be used to perform a Cross Site Scripting attack Example request: `https://x.x.x.x/HelpDeskTab/rcResults.asp?result=<script>alert(document.cookie)</script>` The same is true for the parameter FileName of /done.asp Eaxmple request: `https://x.x.x.x/done.asp?FileName=";</script><script>alert(1);a="&PathData=&originalName=shell.aspx&FileSize=4388&TimeElapsed=00:00:00.078`
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Automated analysis
medium priorityMedium CVSS severity and required authentication plus user interaction limit impact, though high EPSS and public exploit references raise the likelihood of attempts.
What it is
Kaseya VSA reflects the 'result' parameter of /HelpDeskTab/rcResults.asp and the 'FileName' parameter of /done.asp back into the response without proper encoding, allowing reflected cross-site scripting. An authenticated user who is tricked into following a crafted link can have script executed in their VSA session context. The flaw is rated medium severity (CVSS 3.1 5.4) and affects the VSA product per the record.
Impact
An attacker can execute arbitrary script in the victim's authenticated VSA session, potentially stealing session cookies or performing actions as that user. The scope change in the CVSS vector indicates the injected script can affect resources beyond the vulnerable component.
Attack surface
Reached over the network via crafted URLs to /HelpDeskTab/rcResults.asp or /done.asp; the CVSS vector requires low privileges (PR:L) and user interaction (UI:R), so the attacker needs a valid low-privileged account and must lure a victim into clicking a link.
Exploitation
Not listed in CISA KEV and no ransomware usage documented; EPSS is high (0.52687, 98.9th percentile) and DIVD references are tagged Exploit, indicating public proof-of-concept material exists.
What to do
- Apply the vendor patch referenced by the DIVD advisory (DIVD-2021-00011) as the first action.
- Encode or validate the 'result' and 'FileName' parameters server-side so reflected input cannot execute as script.
- Deploy a WAF rule blocking script payloads in requests to /HelpDeskTab/rcResults.asp and /done.asp.
- Restrict VSA access to trusted networks and enforce least privilege on accounts that can reach these endpoints.
- Set session cookies HttpOnly and SameSite to limit cookie theft via XSS.
Detection
- Search web logs for requests to /HelpDeskTab/rcResults.asp or /done.asp containing script tags, event handlers, or encoded equivalents in the result or FileName parameters.
- Alert on outbound or unusual script content in responses from these endpoints.
- Monitor for anomalous authenticated sessions or cookie reuse following visits to crafted links.
- Review VSA audit logs for unexpected actions taken by low-privileged accounts shortly after suspicious URL access.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://csirt.divd.nl/2021/07/07/Kaseya-Limited-Disclosure/ | PatchThird Party Advisory |
| https://csirt.divd.nl/CVE-2021-30119 | ExploitThird Party Advisory |
| https://csirt.divd.nl/DIVD-2021-00011 | PatchThird Party Advisory |
| https://csirt.divd.nl/2021/07/07/Kaseya-Limited-Disclosure/ | PatchThird Party Advisory |
| https://csirt.divd.nl/CVE-2021-30119 | ExploitThird Party Advisory |
| https://csirt.divd.nl/DIVD-2021-00011 | PatchThird Party Advisory |
Track CVE-2021-30119 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-30119), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.