XSS Vulnerability in Quest KACE Systems Management Appliance Server Center
CVE-2019-13081

5.4MEDIUM

Key Information:

Vendor

Quest

Vendor
CVE Published:
6 November 2019

What is CVE-2019-13081?

The Quest KACE Systems Management Appliance Server Center version 9.1.317 contains a Cross-Site Scripting vulnerability. An authenticated user can exploit this flaw through the title field in the /common/ticket_associated_tickets.php service desk ticket functionality. This may allow the attacker to inject and execute arbitrary JavaScript in the browser of any service desk user, leading to potential security breaches.

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.