Record summary

CVE-2018-11133 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.

Description

The 'fmt' parameter of the '/common/run_cross_report.php' script in the the Quest KACE System Management Appliance 8.0.318 is vulnerable to cross-site scripting.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Nuclei templates

1
ProjectDiscoveryMEDIUMQuest KACE SMA /common/run_cross_report.php 'fmt' XSSCVSS 6.1

The 'fmt' parameter of the '/common/run_cross_report.php' script in the the Quest KACE System Management Appliance 8.0.318 is vulnerable to cross-site scripting.

Impact

Attackers can execute arbitrary JavaScript in victims' browsers, potentially stealing session cookies, credentials, or performing actions on behalf of users.

Remediation

Upgrade to a patched version of Quest KACE SMA or apply vendor-provided security updates.

WeaknessesCWE-79
Authorsiamnoooob, pdresearch
Template tagscvecve2018xssquestkacesmavuln
CVSS vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:quest:kace_system_management_appliance:8.0.318:*:*:*:*:*:*:*
Shodan: title:"KACE Systems Management"

Source: ProjectDiscovery

References

2