PT-2018-10324 · Quest · Quest Kace System Management Appliance

Publicado

2018-05-31

·

Atualizado

2018-06-28

·

CVE-2018-11133

CVSS v3.1

6.1

Média

VetorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Quest KACE System Management Appliance version 8.0.318
Description The issue concerns a cross-site scripting vulnerability in the '/common/run cross report.php' script. Specifically, the fmt parameter is vulnerable.
Recommendations For Quest KACE System Management Appliance version 8.0.318, consider restricting access to the '/common/run cross report.php' script until a patch is available. As a temporary workaround, avoid using the fmt parameter in the affected script to minimize the risk of exploitation.

Exploit

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-11133

Produtos afetados

Quest Kace System Management Appliance