SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2020-35720

Stored XSS in Quest Policy Authority 8.1.2.200 allows remote attackers to store malicious code in multiple fields (first name, last name, and logon name) when creating or modifying a user via the submitUser.jsp file.

MEDIUM 5.4EPSS 1.23%

Does this matter?

Lower severity and a low EPSS score (1.23%). Track it; it rarely justifies an emergency change on its own.

Description

Stored XSS in Quest Policy Authority 8.1.2.200 allows remote attackers to store malicious code in multiple fields (first name, last name, and logon name) when creating or modifying a user via the submitUser.jsp file. NOTE: This vulnerability only affects products that are no longer supported by the maintainer

CVSS 3.1
5.4 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
EPSS
1.23% probability · 67th percentile
CISA KEV
Not listed
Weakness
CWE-79
Affected
quest/policy authority for unified communications
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.