CVE-2019-13080
Summary
| CVE | CVE-2019-13080 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-11-06 15:15:00 UTC |
| Updated | 2019-11-07 21:16:00 UTC |
| Description | Quest KACE Systems Management Appliance Server Center 9.1.317 has an XSS vulnerability (via an SVG image and HTML file) that allows an authenticated user to execute arbitrary JavaScript in an administrator's browser. |
Risk And Classification
Problem Types: CWE-79
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Quest | Kace Systems Management Appliance | 9.1.317 | All | All | All |
| Application | Quest | Kace Systems Management Appliance | 9.1.317 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Quest response to Certezza vulnerability report (311388) | MISC | support.quest.com | Vendor Advisory |
| KACE Systems Management Appliance (K1000) | Endpoint Management | MISC | www.quest.com | Product |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.