Vulnerability Description
The 'reportID' parameter received by the '/common/run_report.php' script in the Quest KACE System Management Appliance 8.0.318 is not sanitized, leading to SQL injection (in particular, an error-based type).
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Quest | Kace System Management Appliance | 8.0.318 |
Related Weaknesses (CWE)
References
- https://www.coresecurity.com/advisories/quest-kace-system-management-appliance-mExploitTechnical DescriptionThird Party Advisory
- https://www.coresecurity.com/advisories/quest-kace-system-management-appliance-mExploitTechnical DescriptionThird Party Advisory
FAQ
What is CVE-2018-11140?
CVE-2018-11140 is a vulnerability with a CVSS score of 9.8 (CRITICAL). The 'reportID' parameter received by the '/common/run_report.php' script in the Quest KACE System Management Appliance 8.0.318 is not sanitized, leading to SQL injection (in particular, an error-based...
How severe is CVE-2018-11140?
CVE-2018-11140 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2018-11140?
Check the references section above for vendor advisories and patch information. Affected products include: Quest Kace System Management Appliance.