CVE-2020-35719
Description
Reflected XSS in Quest Policy Authority 8.1.2.200 allows remote attackers to inject malicious code into the browser via a specially crafted link to the /WebCM/Applications/Search/index.jsp file via the added parameter. NOTE: This vulnerability only affects products that are no longer supported by the maintainer
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Reflected XSS in Quest Policy Authority 8.1.2.200 allows remote attackers to inject malicious code via a crafted link to /WebCM/Applications/Search/index.jsp.
Vulnerability
A reflected cross-site scripting (XSS) vulnerability exists in Quest Policy Authority for Unified Communications version 8.1.2.200. The flaw resides in the /WebCM/Applications/Search/index.jsp file, where the added parameter is reflected in the response without proper sanitization or encoding. This allows an attacker to inject arbitrary HTML or JavaScript code that executes in the victim's browser. The product has reached end-of-life and is no longer supported by the vendor [1].
Exploitation
An attacker must craft a malicious link containing a JavaScript payload in the added parameter and trick a user into clicking it. No authentication is required. For example, a link such as https://target/WebCM/Applications/Search/index.jsp?added= would cause the injected script to execute in the context of the application domain when visited [1].
Impact
Successful exploitation allows the attacker to execute arbitrary JavaScript within the security context of the vulnerable application. This can lead to session hijacking, credential theft, defacement, or redirection to malicious sites. The attack is performed in the context of the victim's session, potentially exposing sensitive data or enabling further attacks [1].
Mitigation
Quest has confirmed that the product has reached end-of-life and has been unsupported for over seven years at the time of disclosure. No patches will be issued [1]. The only mitigation is to upgrade to a supported product or restrict access to the vulnerable application as per organizational risk assessment.
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Quest/Policy Authoritydescription
- Range: = 8.1.2.200
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2News mentions
0No linked articles in our index yet.