CVE-2020-35720: XSS
UNSUPPORTED WHEN ASSIGNED Stored XSS in Quest Policy Authority 8.1.2.200 allows remote attackers to store malicious code in multiple fields (first name, last name, and logon name) when creating or modifying a user via the submitUser.jsp file. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2020-35720.
What is the severity of CVE-2020-35720?
The severity of CVE-2020-35720 is medium (5.4).
How does CVE-2020-35720 impact Quest Policy Authority 8.1.2.200?
CVE-2020-35720 allows remote attackers to store malicious code in multiple fields (first name, last name, and logon name) when creating or modifying a user via the submitUser.jsp file.
How can I fix CVE-2020-35720?
The vendor has not provided a fix for CVE-2020-35720 as it is unsupported when assigned.
Where can I find more information about CVE-2020-35720?
You can find more information about CVE-2020-35720 at the following references: [Link 1](https://clandestinelabs.io/security-advisories/advisory-multiple-vulnerabilities-in-quest-policy-authority-for-unified-communications), [Link 2](https://un4gi.io/blog/multiple-vulnerabilities-in-quest-policy-authority-for-unified-communications).