CVE-2020-35721: XSS
UNSUPPORTED WHEN ASSIGNED Reflected XSS in Quest Policy Authority 8.1.2.200 allows remote attackers to inject malicious code into the browser via a specially crafted link to the BrowseAssets.do file via the title parameter. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this security issue?
The vulnerability ID of this security issue is CVE-2020-35721.
What is the severity rating of CVE-2020-35721?
The severity rating of CVE-2020-35721 is medium with a score of 5.4.
What is the affected software version?
The affected software version is Quest Policy Authority 8.1.2.200.
How can remote attackers exploit this vulnerability?
Remote attackers can exploit this vulnerability by injecting malicious code into the browser via a specially crafted link to the BrowseAssets.do file using the title parameter.
Are there any known fixes for this vulnerability?
There are no known fixes for this vulnerability as the product is no longer supported.