SQL Injection Vulnerability in Quest KACE System Management Appliance
CVE-2018-11136

9.8CRITICAL

Key Information:

Vendor

Quest

Vendor
CVE Published:
31 May 2018

What is CVE-2018-11136?

The 'orgID' parameter in the '/common/download_agent_installer.php' script of the Quest KACE System Management Appliance 8.0.318 is susceptible to SQL injection attacks. This vulnerability occurs because the parameter input is not properly sanitized, which can allow attackers to manipulate database queries. Exploitation of this issue can lead to data exposure and unauthorized access to sensitive information within the application.

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2018-11136 : SQL Injection Vulnerability in Quest KACE System Management Appliance