Reflected XSS Vulnerability in Quest KACE Systems Management Appliance
CVE-2019-12917
6.1MEDIUM
What is CVE-2019-12917?
A reflected XSS vulnerability has been identified within the Quest KACE Systems Management Appliance Server Center version 9.1.317. This issue arises through the userui/software_library.php component, where improper handling of PATH_INFO allows an attacker to inject malicious scripts. Exploitation of this vulnerability may enable unauthorized actions, leading to potential unauthorized access or harmful interactions with users accessing the affected interface. Users are advised to implement the latest security patches and follow best practices for web application security to mitigate potential risks.