CVE-2019-11604: XSS
An issue was discovered in Quest KACE Systems Management Appliance before 9.1. The script at /service/kbotservicenotsoap.php is vulnerable to unauthenticated reflected XSS when user-supplied input to the METHOD GET parameter is processed by the web application. Since the application does not properly validate and sanitize this parameter, it is possible to place arbitrary script code into the context of the same page.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-11604?
CVE-2019-11604 is a vulnerability in Quest KACE Systems Management Appliance before 9.1 that allows unauthenticated reflected XSS.
How severe is CVE-2019-11604?
CVE-2019-11604 has a severity rating of 6.1, which is considered medium.
What software is affected by CVE-2019-11604?
Quest KACE Systems Management Appliance versions up to and including 9.1 are affected by CVE-2019-11604.
What is the Common Weakness Enumeration (CWE) for CVE-2019-11604?
CVE-2019-11604 is classified under CWE-79, which is Cross-Site Scripting (XSS).
How can I fix the vulnerability in Quest KACE Systems Management Appliance?
To fix the vulnerability, it is recommended to upgrade to a version later than 9.1 of Quest KACE Systems Management Appliance.