Reflected XSS in Web Compliance Manager of Quest Policy Authority
CVE-2020-35203

6.1MEDIUM

Key Information:

Vendor

Quest

Vendor
CVE Published:
11 January 2021

What is CVE-2020-35203?

A reflected cross-site scripting (XSS) vulnerability in the Web Compliance Manager of Quest Policy Authority version 8.1.2.200 allows attackers to exploit a flaw via specially crafted links to the initFile.jsp file. This vulnerability enables the injection of malicious scripts into the user’s browser, increasing the risk of unauthorized data access and manipulation. It's important to note that this issue affects only unsupported versions of the product, emphasizing the necessity for users to stay updated with vendor support.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2020-35203 : Reflected XSS in Web Compliance Manager of Quest Policy Authority