VYPR
Unrated severityNVD Advisory· Published Jan 11, 2021· Updated Aug 4, 2024

CVE-2020-35727

CVE-2020-35727

Description

Reflected XSS in Quest Policy Authority 8.1.2.200 allows remote attackers to inject malicious code into the browser via a specially crafted link to the BrowseDirs.do file via the title parameter. NOTE: This vulnerability only affects products that are no longer supported by the maintainer

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Reflected XSS in Quest Policy Authority 8.1.2.200 allows injection of malicious scripts via crafted link to BrowseDirs.do with title parameter. Product is end-of-life.

Vulnerability

Reflected Cross-Site Scripting (XSS) vulnerability in Quest Policy Authority 8.1.2.200 exists in the BrowseDirs.do file through the title parameter. An attacker can inject arbitrary JavaScript code via a specially crafted link. No authentication is required to exploit this vulnerability. [1]

Exploitation

An attacker constructs a malicious URL containing a crafted title parameter with JavaScript payload. When a victim clicks on the link, the browser renders the injected script in the context of the application, executing it without any user interaction beyond clicking the link. [1]

Impact

Successful exploitation allows the attacker to execute arbitrary JavaScript in the victim's browser, potentially leading to theft of session cookies, defacement, or actions on behalf of the authenticated user. The attacker gains the same access as the victim within the application. [1]

Mitigation

Quest Policy Authority 8.1.2.200 is end-of-life and no longer supported by the vendor. No security patch is available or planned. The only mitigation is to upgrade or replace the product with a supported alternative. [1]

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.