Security Advisory

CVE-2020-35206

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2021-01-11 02:51:30
Last updated 2024-08-04 17:02:07
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

Reflected XSS in Web Compliance Manager in Quest Policy Authority version 8.1.2.200 allows attackers to inject malicious code into the browser via a specially crafted link to the cConn.jsp file via the ur parameter. NOTE: This vulnerability only affects products that are no longer supported by the maintainer