First published: Tue Aug 02 2022(Updated: )
A SQL injection vulnerability exists within Quest KACE Systems Management Appliance (SMA) through 12.0 that can allow for remote code execution via download_agent_installer.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Quest KACE Systems Management Appliance | <12.1.168 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-29807 is a SQL injection vulnerability within Quest KACE Systems Management Appliance (SMA) through version 12.0 that can allow for remote code execution.
The severity of CVE-2022-29807 is critical with a severity value of 9.8.
Quest KACE Systems Management Appliance (SMA) versions up to and excluding 12.1.168 are affected by CVE-2022-29807.
CVE-2022-29807 can be exploited through the download_agent_installer.php file, allowing for remote code execution.
You can find more information about CVE-2022-29807 on the Quest support website at the following link: [Quest Support Link](https://support.quest.com/kace-systems-management-appliance/kb/338162/quest-response-to-kace-sma-vulnerabilities-cve-2022-29807)