First published: Thu May 31 2018(Updated: )
The script '/adminui/error_details.php' in the Quest KACE System Management Appliance 8.0.318 allows authenticated users to conduct PHP object injection attacks.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Quest KACE Systems Management Appliance | =8.0.318 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-11135 is considered a high severity issue due to its potential for PHP object injection attacks.
To fix CVE-2018-11135, you should update the Quest KACE System Management Appliance to the latest version that addresses this vulnerability.
CVE-2018-11135 can facilitate PHP object injection attacks, which may allow an attacker to manipulate application logic.
Only authenticated users of the Quest KACE System Management Appliance version 8.0.318 are affected by CVE-2018-11135.
Exploiting CVE-2018-11135 can lead to unauthorized actions being performed on the Quest KACE System Management Appliance.