SQL Injection Vulnerability in Quest KACE System Management Appliance
CVE-2018-11136
9.8CRITICAL
What is CVE-2018-11136?
The 'orgID' parameter in the '/common/download_agent_installer.php' script of the Quest KACE System Management Appliance 8.0.318 is susceptible to SQL injection attacks. This vulnerability occurs because the parameter input is not properly sanitized, which can allow attackers to manipulate database queries. Exploitation of this issue can lead to data exposure and unauthorized access to sensitive information within the application.