>> All posts

CVE-2021-30117: Kaseya VSA SQL Injection Vulnerability Exploitation (CVE-2021-30117)

The short version: The API call /InstallTab/exportFldr.asp is vulnerable to a semi-authenticated boolean-based blind SQL injection in the parameter fldrId. A valid session id is required for exploitation. BreachRisk discovers exposed instances from your attack surface and flags this finding so you can prioritize by real-world breach risk.

At a glance

FactDetail
Our severity takeHigh — BreachRisk score 6.9 (impact 4, likelihood 4)
CVSS v3.1 (NVD)Unknown at time of writing
In CISA KEV?Unknown at time of writing — check the KEV catalog
Known exploited?Unknown at time of writing
Requires authenticated session?Unknown at time of writing
CVECVE-2021-30117

What you need to know

Exposed Kaseya VSA Server appears vulnerable to exploitation of sql injection vulnerability (CVE-2021-30117).

  • How they find it — internet-facing exposure of the affected product is discoverable by routine scanning.
  • How they use it — attackers exploit the vulnerability against reachable instances.
  • What it leads to — compromise of the affected service and, depending on placement, a foothold for further movement.

How serious we see it

High — based on BreachRisk impact and likelihood scoring for this threat definition (score 6.9/9). Treat internet-facing instances as priority; confirm exposure and patch status before assuming you're clear.

Recommendations

  1. Apply latest security update to exposed Kaseya VSA Server.

How BreachRisk sees it

BreachRisk discovers internet-facing assets tied to this threat, fingerprints the product where possible, and flags exposure for CVE-2021-30117. Where authorized, it can go beyond detection with a bounded, non-disruptive check rather than leaving you with a maybe. Continuous outside-in coverage means the exposed service is already on your radar ranked by how it actually gets used against you.

References

See your cyber risk, proven.