CVE-2019-13076: Quest KACE Systems Management Appliance
High severity, CVSS 8.8. EPSS: 1.2% chance of exploitation in the next 30 days.
Quest KACE Systems Management Appliance Server Center 9.1.317 is vulnerable to SQL injection. An authenticated user has the ability to execute arbitrary commands against the database. The affected component is /userui/ticket_list.php, and affected parameters are order[0][column] and order[0][dir].
Affected products
- Quest KACE Systems Management Appliance: version 9.1.317 only
Published 2019-11-06. Last modified 2026-06-17.