quest policy-authority-unified-communications CVE-2020-35725 is a vulnerability in Quest Software Policy Authority Unified Communications
Published on January 11, 2021

Reflected XSS in Quest Policy Authority 8.1.2.200 allows remote attackers to inject malicious code into the browser via a specially crafted link to the /WebCM/index.jsp file via the msg parameter. NOTE: This vulnerability only affects products that are no longer supported by the maintainer

NVD


Products Associated with CVE-2020-35725

Want to know whenever a new CVE is published for Quest Software Policy Authority Unified Communications? stack.watch will email you.

 

Exploit Probability

EPSS
0.38%
Percentile
58.70%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.