CVE-2019-13077: XSS
Quest KACE Systems Management Appliance Server Center 9.1.317 has an XSS vulnerability (via the samdetailtitled.php SAMTYPE parameter) that allows an attacker to create a malicious link in order to attack authenticated users.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for Quest KACE Systems Management Appliance Server Center 9.1.317?
The vulnerability ID for Quest KACE Systems Management Appliance Server Center 9.1.317 is CVE-2019-13077.
What is the severity of CVE-2019-13077?
The severity of CVE-2019-13077 is medium with a CVSS score of 6.1.
How does the XSS vulnerability in Quest KACE Systems Management Appliance Server Center 9.1.317 work?
The XSS vulnerability in Quest KACE Systems Management Appliance Server Center 9.1.317 allows an attacker to create a malicious link that can be used to attack authenticated users.
What software versions are affected by CVE-2019-13077?
Quest KACE Systems Management Appliance Server Center 9.1.317 is affected by CVE-2019-13077.
Where can I find more information about CVE-2019-13077?
More information about CVE-2019-13077 can be found at the following links: [Quest Knowledge Base](https://support.quest.com/kb/311388/quest-response-to-certezza-vulnerability-report) and [Quest KACE Systems Management Appliance](https://www.quest.com/products/kace-systems-management-appliance/).