Security Advisory

CVE-2020-35720

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2021-01-11 02:55:38
Last updated 2024-08-04 17:09:15
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

Stored XSS in Quest Policy Authority 8.1.2.200 allows remote attackers to store malicious code in multiple fields (first name, last name, and logon name) when creating or modifying a user via the submitUser.jsp file. NOTE: This vulnerability only affects products that are no longer supported by the maintainer