CVE-2013-10034 describes an unrestricted file upload vulnerability in Kaseya KServer versions prior to 6.3.0.2, allowing unauthenticated attackers to upload arbitrary files, including executable ASP files, to web-accessible directories. This critical vulnerability (CVSS 9.3) enables remote code execution with IUSR account privileges due to a lack of authentication and input sanitation on the uploadImage.asp endpoint. Exploit code is publicly available via a Metasploit module, and while it is not on the KEV catalog, its high EPSS and FAUCET Risk Score, coupled with significant community discussion, indicate a high likelihood of exploitation. The vulnerability was resolved by removing the vulnerable endpoint in version 6.3.0.2.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Kaseya | KServer | >= 0, < 6.3.0.2CNA affecteddefault unaffected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.