CVE-2015-2863

EXPLOITED NUCLEI

Kaseya Virtual System Administrator 7.x < 7.0.0.29, 8.x < 8.0.0.18, 9.0 < 9.0.0.14, 9.1 < 9.1.0.4 - Open Redirect

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2015-2863 has been observed exploited in the wild (reported by VulnCheck KEV). EIP tracks 1 public exploit from researchers including Pedro Ribeiro. A Nuclei detection template is also available.

AI-analyzed exploit summary The document describes two vulnerabilities in Kaseya Virtual System Administrator: an authenticated arbitrary file download (CVE-2015-2862) and an unauthenticated open redirect (CVE-2015-2863). It includes technical details, affected versions, and mitigation steps but does not contain executable exploit code.

Description

Open redirect vulnerability in Kaseya Virtual System Administrator (VSA) 7.x before 7.0.0.29, 8.x before 8.0.0.18, 9.0 before 9.0.0.14, and 9.1 before 9.1.0.4 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.

Exploits (1)

exploitdb WRITEUP
by Pedro Ribeiro · textwebappswindows
https://www.exploit-db.com/exploits/37621

The document describes two vulnerabilities in Kaseya Virtual System Administrator: an authenticated arbitrary file download (CVE-2015-2862) and an unauthenticated open redirect (CVE-2015-2863). It includes technical details, affected versions, and mitigation steps but does not contain executable exploit code.

Classification
Writeup 100%
Attack Type
Info Leak | Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: Kaseya Virtual System Administrator v7 to v9.1
Auth required
Prerequisites: Valid login credentials for file download vulnerability
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Nuclei Templates (1)

Kaseya Virtual System Administrator - Open Redirect
MEDIUMby 0x_Akoko,AmirHossein Raeisi

References (1)

Core 1
Core References
Third Party Advisory, US Government Resource third-party-advisory x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/919604

Scores

EPSS 0.4904
EPSS Percentile 97.8%

Details

VulnCheck KEV 2023-12-15
Status published
Products (1)
kaseya/virtual_system_administrator 7.0 - 7.0.0.29
Published Jul 20, 2015
Tracked Since Feb 18, 2026