Quest KACE Systems Management Appliance Server Center 9.1.317 has an XSS vulnerability (via an SVG image and HTML file) that allows an authenticated user to execute arbitrary JavaScript in an administrator's browser.
References
Link | Resource |
---|---|
https://support.quest.com/kb/311388/quest-response-to-certezza-vulnerability-report | Vendor Advisory |
https://www.quest.com/products/kace-systems-management-appliance/ | Product |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: mitre
Published: 2019-11-06T14:53:54
Updated: 2019-11-06T14:53:54
Reserved: 2019-06-30T00:00:00
Link: CVE-2019-13080
JSON object: View
NVD Information
Status : Analyzed
Published: 2019-11-06T15:15:11.423
Modified: 2019-11-07T21:16:00.083
Link: CVE-2019-13080
JSON object: View
Redhat Information
No data.
CWE