Vulnerability Description
An issue was discovered in Quest KACE Systems Management Appliance before 9.1. The script at /service/kbot_service_notsoap.php is vulnerable to unauthenticated reflected XSS when user-supplied input to the METHOD GET parameter is processed by the web application. Since the application does not properly validate and sanitize this parameter, it is possible to place arbitrary script code into the context of the same page.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Quest | Kace Systems Management Appliance | < 9.1 |
Related Weaknesses (CWE)
References
- http://packetstormsecurity.com/files/153053/Quest-KACE-Systems-Management-AppliaExploitThird Party AdvisoryVDB Entry
- http://seclists.org/fulldisclosure/2019/May/40ExploitMailing ListThird Party Advisory
- https://www.rcesecurity.com/Third Party Advisory
- http://packetstormsecurity.com/files/153053/Quest-KACE-Systems-Management-AppliaExploitThird Party AdvisoryVDB Entry
- http://seclists.org/fulldisclosure/2019/May/40ExploitMailing ListThird Party Advisory
- https://www.rcesecurity.com/Third Party Advisory
FAQ
What is CVE-2019-11604?
CVE-2019-11604 is a vulnerability with a CVSS score of 6.1 (MEDIUM). An issue was discovered in Quest KACE Systems Management Appliance before 9.1. The script at /service/kbot_service_notsoap.php is vulnerable to unauthenticated reflected XSS when user-supplied input t...
How severe is CVE-2019-11604?
CVE-2019-11604 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-11604?
Check the references section above for vendor advisories and patch information. Affected products include: Quest Kace Systems Management Appliance.