SQL Injection Vulnerability in Quest KACE Systems Management Appliance
CVE-2019-13078
8.8HIGH
What is CVE-2019-13078?
The Quest KACE Systems Management Appliance Server Center version 9.1.317 is susceptible to an SQL injection vulnerability located in the /common/user_profile.php component. This flaw allows authenticated users to manipulate the 'sort_column' parameter, potentially enabling them to execute arbitrary SQL commands against the database. Such unauthorized command execution can compromise data integrity and lead to unauthorized information disclosure.