CVE-2019-12918: Quest KACE Systems Management Appliance

Critical severity, CVSS 9.8. EPSS: 1.1% chance of exploitation in the next 30 days.

Quest KACE Systems Management Appliance Server Center version 9.1.317 is vulnerable to SQL injection. The affected file is software_library.php and affected parameters are order[0][column] and order[0][dir].

Affected products

  • Quest KACE Systems Management Appliance: version 9.1.317 only

Published 2019-11-06. Last modified 2026-06-17.