CVE-2020-35723
Description
Reflected XSS in Quest Policy Authority 8.1.2.200 allows remote attackers to inject malicious code into the browser via a specially crafted link to the ReportPreview.do file via the referer parameter. NOTE: This vulnerability only affects products that are no longer supported by the maintainer
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Reflected XSS in Quest Policy Authority 8.1.2.200 allows unauthenticated attackers to inject scripts via the referer parameter in ReportPreview.do.
Vulnerability
A reflected cross-site scripting (XSS) vulnerability exists in Quest Policy Authority for Unified Communications version 8.1.2.200. The ReportPreview.do file reflects the referer parameter without proper sanitization or encoding, allowing an attacker to inject arbitrary HTML and JavaScript. The product has reached end-of-life and is no longer supported by the vendor. [1]
Exploitation
An attacker can exploit this vulnerability by crafting a malicious link containing JavaScript in the referer parameter and convincing a victim to click it. No authentication is required to trigger the reflected XSS. When the victim clicks the link, the injected script executes in the context of the application's origin. [1]
Impact
Successful exploitation allows the attacker to execute arbitrary JavaScript in the victim's browser within the session context of the Quest Policy Authority application. This can lead to session hijacking, credential theft, or other malicious actions. Since the product is end-of-life, no remediation is available. [1]
Mitigation
Quest has confirmed that the product is end-of-life and has been unsupported for over seven years. No patch is available. Organizations using this product should immediately discontinue its use and migrate to a supported alternative. [1]
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Quest/Policy Authoritydescription
- Range: = 8.1.2.200
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2News mentions
0No linked articles in our index yet.