SQL Injection Vulnerability in Quest KACE Systems Management Appliance Server Center
CVE-2019-12918
9.8CRITICAL
What is CVE-2019-12918?
The Quest KACE Systems Management Appliance Server Center version 9.1.317 is exposed to a SQL injection vulnerability that arises due to improper sanitization of user input in the software_library.php file. Attackers can exploit this vulnerability by manipulating parameters order[0][column] and order[0][dir], potentially leading to unauthorized access to sensitive data or system compromise.