VulnerabilityModified
CVE-2021-44030
Quest KACE Desktop Authority before 11.2 allows XSS because it does not prevent untrusted HTML from reaching the jQuery.htmlPrefilter method of jQuery.
MEDIUM 6.1EPSS 4.16%
Does this matter?
Lower severity and a low EPSS score (4.16%). Track it; it rarely justifies an emergency change on its own.
Description
Quest KACE Desktop Authority before 11.2 allows XSS because it does not prevent untrusted HTML from reaching the jQuery.htmlPrefilter method of jQuery.
- CVSS 3.1
- 6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 4.16% probability · 90th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- quest/kace desktop authority
- Source
- cve@mitre.org
References
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.