CVE-2020-35725
Description
Reflected XSS in Quest Policy Authority 8.1.2.200 allows remote attackers to inject malicious code into the browser via a specially crafted link to the /WebCM/index.jsp file via the msg parameter. NOTE: This vulnerability only affects products that are no longer supported by the maintainer
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Reflected XSS in Quest Policy Authority 8.1.2.200 allows unauthenticated attackers to inject arbitrary JavaScript via the msg parameter in /WebCM/index.jsp.
Vulnerability
A reflected cross-site scripting (XSS) vulnerability exists in Quest Policy Authority for Unified Communications version 8.1.2.200. The msg parameter in /WebCM/index.jsp is echoed into the response without proper sanitization or encoding [1]. The product is end-of-life and has been unsupported for over seven years at the time of disclosure; no patches are available [1].
Exploitation
An attacker can craft a malicious link containing a JavaScript payload in the msg parameter and trick an authenticated or unauthenticated user into clicking it. The request requires no authentication. The injected script executes in the victim's browser within the security context of the application [1].
Impact
Successful exploitation allows the attacker to execute arbitrary JavaScript in the victim's browser. This can lead to session hijacking, cookie theft, redirection to malicious sites, or other actions on behalf of the victim within the application. The impact is limited to the browser session and data accessible to the application [1].
Mitigation
Quest confirmed the product is end-of-life and will not issue any patches. Users must migrate to a supported alternative or remove the product from their environment. This vulnerability is not listed on CISA's Known Exploited Vulnerabilities (KEV) catalog at the time of writing [1].
AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Quest/Policy Authoritydescription
- Range: = 8.1.2.200
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2News mentions
0No linked articles in our index yet.