VYPR
Unrated severityNVD Advisory· Published Jan 11, 2021· Updated Nov 19, 2024

CVE-2020-35725

CVE-2020-35725

Description

Reflected XSS in Quest Policy Authority 8.1.2.200 allows remote attackers to inject malicious code into the browser via a specially crafted link to the /WebCM/index.jsp file via the msg parameter. NOTE: This vulnerability only affects products that are no longer supported by the maintainer

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Reflected XSS in Quest Policy Authority 8.1.2.200 allows unauthenticated attackers to inject arbitrary JavaScript via the msg parameter in /WebCM/index.jsp.

Vulnerability

A reflected cross-site scripting (XSS) vulnerability exists in Quest Policy Authority for Unified Communications version 8.1.2.200. The msg parameter in /WebCM/index.jsp is echoed into the response without proper sanitization or encoding [1]. The product is end-of-life and has been unsupported for over seven years at the time of disclosure; no patches are available [1].

Exploitation

An attacker can craft a malicious link containing a JavaScript payload in the msg parameter and trick an authenticated or unauthenticated user into clicking it. The request requires no authentication. The injected script executes in the victim's browser within the security context of the application [1].

Impact

Successful exploitation allows the attacker to execute arbitrary JavaScript in the victim's browser. This can lead to session hijacking, cookie theft, redirection to malicious sites, or other actions on behalf of the victim within the application. The impact is limited to the browser session and data accessible to the application [1].

Mitigation

Quest confirmed the product is end-of-life and will not issue any patches. Users must migrate to a supported alternative or remove the product from their environment. This vulnerability is not listed on CISA's Known Exploited Vulnerabilities (KEV) catalog at the time of writing [1].

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.