Reflected XSS in Quest Policy Authority Affects Legacy Systems
CVE-2020-35721

5.4MEDIUM

Key Information:

Vendor

Quest

Vendor
CVE Published:
11 January 2021

What is CVE-2020-35721?

A vulnerability in Quest Policy Authority permits remote adversaries to exploit reflected cross-site scripting (XSS) through the title parameter in crafted links to the BrowseAssets.do file. This issue primarily affects unsupported product versions, allowing attackers to inject malicious scripts into users’ browsers, potentially leading to compromised confidentiality and integrity of user data.

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.