Vulnerability Description
The '/common/ajax_email_connection_test.php' script in the Quest KACE System Management Appliance 8.0.318 is accessible by any authenticated user and can be abused to execute arbitrary commands on the system. This script is vulnerable to command injection via the unsanitized user input 'TEST_SERVER' sent to the script via the POST method.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Quest | Kace System Management Appliance | 8.0.318 |
Related Weaknesses (CWE)
References
- https://www.coresecurity.com/advisories/quest-kace-system-management-appliance-mExploitTechnical DescriptionThird Party Advisory
- https://www.coresecurity.com/advisories/quest-kace-system-management-appliance-mExploitTechnical DescriptionThird Party Advisory
FAQ
What is CVE-2018-11139?
CVE-2018-11139 is a vulnerability with a CVSS score of 8.8 (HIGH). The '/common/ajax_email_connection_test.php' script in the Quest KACE System Management Appliance 8.0.318 is accessible by any authenticated user and can be abused to execute arbitrary commands on the...
How severe is CVE-2018-11139?
CVE-2018-11139 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-11139?
Check the references section above for vendor advisories and patch information. Affected products include: Quest Kace System Management Appliance.