Kaseya Left Customer Portal Vulnerable to 2015 Flaw in its Own Software
Krebs on Security
JULY 8, 2021
Also on July 3, security incident response firm Mandiant notified Kaseya that their billing and customer support site — portal.kaseya.net — was vulnerable to CVE-2015-2862 , a “directory traversal” vulnerability in Kaseya VSA that allows remote users to read any files on the server using nothing more than a Web browser.
Let's personalize your content