VYPR
High severity8.8NVD Advisory· Published Feb 13, 2020· Updated Jun 17, 2026

CVE-2015-6589

CVE-2015-6589

Description

Directory traversal vulnerability in Kaseya Virtual System Administrator (VSA) 7.0.0.0 before 7.0.0.33, 8..0.0.0 before 8.0.0.23, 9.0.0.0 before 9.0.0.19, and 9.1.0.0 before 9.1.0.9 allows remote authenticated users to write to and execute arbitrary files due to insufficient restrictions in file paths to json.ashx.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • cpe:2.3:a:kaseya:virtual_system_administrator:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:kaseya:virtual_system_administrator:*:*:*:*:*:*:*:*range: >=7.0.0.0,<7.0.0.33
    • (no CPE)range: <7.0.0.33, <8.0.0.23, <9.0.0.19, <9.1.0.9
  • Kaseya/Virtual System Administratordescription

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.