Loading
The 'IMAGES_JSON' and 'attachments_to_remove[]' parameters of the '/adminui/advisory.php' script in the Quest KACE System Management Virtual Appliance 8.0.318 can be abused to write and delete files respectively via Directory Traversal. Files can be at any location where the 'www' user has write permissions.
Use CWE-22, Quest vendor hub and Kace System Management Appliance product page to widen CVE-2018-11141 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2018-11138, CVE-2018-11140 and CVE-2018-11136 for nearby disclosures in the same product family.