Vulnerabilities > Quest > Kace Systems Management Appliance > 9.1.317

DATE CVE VULNERABILITY TITLE RISK
2019-11-06 CVE-2019-12918 SQL Injection vulnerability in Quest Kace Systems Management Appliance 9.1.317
Quest KACE Systems Management Appliance Server Center version 9.1.317 is vulnerable to SQL injection.
network
low complexity
quest CWE-89
critical
9.8
2019-11-06 CVE-2019-12917 Cross-site Scripting vulnerability in Quest Kace Systems Management Appliance 9.1.317
A reflected XSS vulnerability exists in Quest KACE Systems Management Appliance Server Center 9.1.317 affecting the userui/software_library.php component via the PATH_INFO.
network
low complexity
quest CWE-79
6.1