CVE-2019-13081

Quest KACE Systems Management Appliance Server Center 9.1.317 has an XSS vulnerability (via the title field in the /common/ticket_associated_tickets.php service desk ticket functionality) that allows an authenticated user to execute arbitrary JavaScript in a service desk user's browser.
Configurations

Configuration 1 (hide)

cpe:2.3:a:quest:kace_systems_management_appliance:9.1.317:*:*:*:*:*:*:*

History

No history.

Information

Published : 2019-11-06 15:15

Updated : 2024-02-04 20:39


NVD link : CVE-2019-13081

Mitre link : CVE-2019-13081

CVE.ORG link : CVE-2019-13081


JSON object : View

Products Affected

quest

  • kace_systems_management_appliance
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')