Vulnerabilities (CVE)

Filtered by vendor Quest Subscribe
Filtered by product Kace Desktop Authority
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-44028 1 Quest 1 Kace Desktop Authority 2022-01-03 4.3 MEDIUM 5.5 MEDIUM
XXE can occur in Quest KACE Desktop Authority before 11.2 because the log4net configuration file might be controlled by an attacker, a related issue to CVE-2018-1285.
CVE-2021-44030 1 Quest 1 Kace Desktop Authority 2021-12-27 4.3 MEDIUM 6.1 MEDIUM
Quest KACE Desktop Authority before 11.2 allows XSS because it does not prevent untrusted HTML from reaching the jQuery.htmlPrefilter method of jQuery.