PT-2019-13019 · Quest · Quest Kace Systems Management Appliance Server Center
Published
2019-11-06
·
Updated
2019-11-07
·
CVE-2019-12917
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Quest KACE Systems Management Appliance Server Center version 9.1.317
Description
A reflected XSS issue exists in the userui/software library.php component via the PATH INFO.
Recommendations
For version 9.1.317, consider restricting access to the userui/software library.php component until a patch is available. As a temporary workaround, avoid using the vulnerable PATH INFO in the affected component to minimize the risk of exploitation.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Quest Kace Systems Management Appliance Server Center