CVE-2021-30117 is a semi-authenticated boolean-based blind SQL injection vulnerability affecting Kaseya VSA. Specifically, the /InstallTab/exportFldr.asp API endpoint is vulnerable through the fldrId parameter. This flaw allows an attacker to extract sensitive information from the database. The vulnerability carries a high CVSS score of 8.8, indicating a critical risk. It has a network attack vector, low attack complexity, and can lead to high impact on confidentiality, integrity, and availability. Successful exploitation requires prior authentication, often achieved via CVE-2021-30116. While not listed in CISA's KEV catalog, this CVE was exploited in the wild by the REvil ransomware group, as evidenced by media coverage. There is no public exploit code available in Metasploit, Nuclei, or ExploitDB, but it has garnered significant community discussion and media attention due to its use in real-world attacks.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 9.5.6CPE matchmatch criteria | cpe:2.3:a:kaseya:vsa:*:*:*:*:-:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.