PT-2018-10332 · Quest · Quest Kace System Management Appliance

Published

2018-05-31

·

Updated

2018-07-02

·

CVE-2018-11140

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Quest KACE System Management Appliance version 8.0.318
Description The issue concerns the '/common/run report.php' script, where the reportID parameter is not properly sanitized. This leads to a SQL injection vulnerability, specifically an error-based type.
Recommendations For Quest KACE System Management Appliance version 8.0.318, consider restricting access to the '/common/run report.php' script until a fix is available, and avoid using the reportID parameter in this endpoint to minimize the risk of exploitation.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-11140

Affected Products

Quest Kace System Management Appliance