CVE-2018-11133: XSS
Published May 31, 2018
·Updated
The 'fmt' parameter of the '/common/runcrossreport.php' script in the the Quest KACE System Management Appliance 8.0.318 is vulnerable to cross-site scripting.
Affected Software
1 affected component
Quest KACE System Management Appliance=8.0.318
Event History
May 31, 2018
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-11133?
CVE-2018-11133 has been assigned a medium severity rating due to its potential for cross-site scripting exploits.
2
How do I fix CVE-2018-11133?
To fix CVE-2018-11133, it is recommended to update the Quest KACE System Management Appliance to the latest version that addresses this vulnerability.
3
What type of vulnerability is CVE-2018-11133?
CVE-2018-11133 is classified as a cross-site scripting (XSS) vulnerability.
4
What are the potential impacts of CVE-2018-11133?
Exploitation of CVE-2018-11133 could allow an attacker to execute malicious scripts in the context of an affected user’s session.
5
Which version of Quest KACE is affected by CVE-2018-11133?
CVE-2018-11133 specifically affects version 8.0.318 of the Quest KACE System Management Appliance.