Reflected XSS Vulnerability in Quest Policy Authority Web Compliance Manager
CVE-2020-35206
6.1MEDIUM
What is CVE-2020-35206?
A reflected cross-site scripting (XSS) vulnerability is present in the Web Compliance Manager of Quest Policy Authority, specifically in version 8.1.2.200. This flaw enables attackers to inject malicious scripts through a crafted link targeting the cConn.jsp file using the 'ur' parameter. It is essential to note that this vulnerability impacts products that are no longer actively maintained, making them particularly susceptible to exploitation.