{"cveID":"CVE-2017-18362","vendorProject":"Kaseya","product":"Virtual System/Server Administrator (VSA)","vulnerabilityName":"Kaseya VSA SQL Injection Vulnerability","dateAdded":"2022-05-24","shortDescription":"ConnectWise ManagedITSync integration for Kaseya VSA is vulnerable to unauthenticated remote commands that allow full direct access to the Kaseya VSA database.","requiredAction":"The impacted product is end-of-life and should be disconnected if still in use.","dueDate":"2022-06-14","knownRansomwareCampaignUse":"Known","notes":"https://nvd.nist.gov/vuln/detail/CVE-2017-18362","cwes":["CWE-89"],"year":2017,"state":"unmapped","stale_reasons":[],"mappings":[],"techniques":[],"mapping_types":[],"has_exploitation_technique":false,"mapping_attack_versions":[],"mapping_domains":[],"sigma_coverage":null,"sigma_rules_tagged_cve":[],"added_after_mapping_snapshot":false,"_source":"kevmap","_built":"2026-08-23 05:47 UTC","_attack_version":"19.2"}