SQL Injection Vulnerability in Quest KACE System Management Appliance
CVE-2018-11140
9.8CRITICAL
What is CVE-2018-11140?
The Quest KACE System Management Appliance version 8.0.318 contains a security vulnerability in which the 'reportID' parameter in the '/common/run_report.php' script is not properly sanitized. This inadequacy allows an attacker to manipulate input and execute SQL injection attacks, potentially leading to unauthorized access to sensitive data and system integrity issues.