CVE-2019-13081: Quest KACE Systems Management Appliance

Medium severity, CVSS 5.4. EPSS: 0.8% chance of exploitation in the next 30 days.

Quest KACE Systems Management Appliance Server Center 9.1.317 has an XSS vulnerability (via the title field in the /common/ticket_associated_tickets.php service desk ticket functionality) that allows an authenticated user to execute arbitrary JavaScript in a service desk user's browser.

Affected products

  • Quest KACE Systems Management Appliance: version 9.1.317 only

Published 2019-11-06. Last modified 2026-06-17.