An unrestricted file upload vulnerability exists in Kaseya KServer versions prior to 6.3.0.2. The uploadImage.asp endpoint allows unauthenticated users to upload files to arbitrary paths via a crafted filename parameter in a multipart/form-data POST request. Due to the lack of authentication and input sanitation, an attacker can upload a file with an .asp extension to a web-accessible directory, which can then be invoked to execute arbitrary code with the privileges of the IUSR account. The vulnerability enables remote code execution without prior authentication and was resolved in version 6.3.0.2 by removing the vulnerable uploadImage.asp endpoint.
History

Thu, 31 Jul 2025 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Kaseya
Kaseya kserver
Vendors & Products Kaseya
Kaseya kserver

Thu, 31 Jul 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 31 Jul 2025 15:00:00 +0000

Type Values Removed Values Added
Description An unrestricted file upload vulnerability exists in Kaseya KServer versions prior to 6.3.0.2. The uploadImage.asp endpoint allows unauthenticated users to upload files to arbitrary paths via a crafted filename parameter in a multipart/form-data POST request. Due to the lack of authentication and input sanitation, an attacker can upload a file with an .asp extension to a web-accessible directory, which can then be invoked to execute arbitrary code with the privileges of the IUSR account. The vulnerability enables remote code execution without prior authentication and was resolved in version 6.3.0.2 by removing the vulnerable uploadImage.asp endpoint.
Title Kaseya < 6.3.0.2 uploadImage.asp Arbitrary File Upload RCE
Weaknesses CWE-434
References
Metrics cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published: 2025-07-31T14:56:30.930Z

Updated: 2025-07-31T19:22:42.274Z

Reserved: 2025-07-30T16:12:07.514Z

Link: CVE-2013-10034

cve-icon Vulnrichment

Updated: 2025-07-31T19:21:39.977Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-07-31T15:15:32.937

Modified: 2025-07-31T18:42:37.870

Link: CVE-2013-10034

cve-icon Redhat

No data.