First published: Wed Nov 06 2019(Updated: )
Quest KACE Systems Management Appliance Server Center 9.1.317 has an XSS vulnerability (via an SVG image and HTML file) that allows an authenticated user to execute arbitrary JavaScript in an administrator's browser.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Quest KACE Systems Management Appliance | =9.1.317 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-13080 is an XSS vulnerability in Quest KACE Systems Management Appliance Server Center 9.1.317.
CVE-2019-13080 allows an authenticated user to execute arbitrary JavaScript in an administrator's browser.
CVE-2019-13080 has a severity rating of medium (5.4).
A patch or update provided by Quest for KACE Systems Management Appliance version 9.1.317 is required to fix CVE-2019-13080.
More information about CVE-2019-13080 can be found on the Quest support website and the official Quest product page.