First published: Wed Dec 22 2021(Updated: )
Quest KACE Desktop Authority before 11.2 allows XSS because it does not prevent untrusted HTML from reaching the jQuery.htmlPrefilter method of jQuery.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Quest KACE Desktop Authority | >=10.0<11.2 | |
>=10.0<11.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-44030 refers to a vulnerability in Quest KACE Desktop Authority that allows XSS attacks by not preventing untrusted HTML from reaching the jQuery.htmlPrefilter method of jQuery.
CVE-2021-44030 has a severity rating of medium and a CVSS score of 6.1.
CVE-2021-44030 affects Quest KACE Desktop Authority versions prior to 11.2.
To fix CVE-2021-44030, it is recommended to update Quest KACE Desktop Authority to version 11.2 or later.
More information about CVE-2021-44030 can be found in the following link: [Quest Response to Desktop Authority Vulnerabilities Prior to 11.2](https://support.quest.com/kace-desktop-authority/kb/336098/quest-response-to-desktop-authority-vulnerabilities-prior-to-11-2)