XSS Vulnerability in Quest KACE Systems Management Appliance
CVE-2022-38220

6.1MEDIUM

Key Information:

Vendor

Quest

Vendor
CVE Published:
1 March 2023

What is CVE-2022-38220?

An XSS vulnerability has been identified in the Quest KACE Systems Management Appliance (SMA) versions up to 12.1. This vulnerability may enable remote attackers to inject arbitrary web scripts or HTML into the application, potentially compromising user sessions and data integrity. Users are advised to apply security patches and follow best practices to mitigate risks associated with this vulnerability.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.