CVE-2019-13081

Quest KACE Systems Management Appliance Server Center 9.1.317 has an XSS vulnerability (via the title field in the /common/ticket_associated_tickets.php service desk ticket functionality) that allows an authenticated user to execute arbitrary JavaScript in a service desk user's browser.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

cpe:2.3:a:quest:kace_systems_management_appliance:9.1.317:*:*:*:*:*:*:*

Information

Published : 2019-11-06 07:15

Updated : 2019-11-07 12:32


NVD link : CVE-2019-13081

Mitre link : CVE-2019-13081


JSON object : View

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Advertisement

dedicated server usa

Products Affected

quest

  • kace_systems_management_appliance