CVE-2022-29807: SQL Injection
A SQL injection vulnerability exists within Quest KACE Systems Management Appliance (SMA) through 12.0 that can allow for remote code execution via downloadagentinstaller.php.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-29807?
CVE-2022-29807 is a SQL injection vulnerability within Quest KACE Systems Management Appliance (SMA) through version 12.0 that can allow for remote code execution.
How severe is the CVE-2022-29807 vulnerability?
The severity of CVE-2022-29807 is critical with a severity value of 9.8.
Which software versions are affected by CVE-2022-29807?
Quest KACE Systems Management Appliance (SMA) versions up to and excluding 12.1.168 are affected by CVE-2022-29807.
How can CVE-2022-29807 be exploited?
CVE-2022-29807 can be exploited through the download_agent_installer.php file, allowing for remote code execution.
Where can I find more information about CVE-2022-29807?
You can find more information about CVE-2022-29807 on the Quest support website at the following link: [Quest Support Link](https://support.quest.com/kace-systems-management-appliance/kb/338162/quest-response-to-kace-sma-vulnerabilities-cve-2022-29807)