CVE-2018-5405 describes a cross-site scripting (XSS) vulnerability in Quest Kace K1000 Appliance versions prior to 9.0.270. An authenticated user with "User Console Only" rights can inject arbitrary JavaScript code on the tickets page. This medium-severity vulnerability (CVSS 5.4) has a low attack complexity and requires user interaction, but could lead to session hijacking, including administrator sessions, due to improper neutralization of user-controlled input. While not listed on the KEV catalog or Hot List, an ExploitDB entry exists (EDB-46956), and it has received some community and media attention, indicating awareness of the flaw.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 9.0.270CPE matchmatch criteria | cpe:2.3:o:quest:kace_systems_management_appliance_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.