Learn about CVE-2020-35720, a Stored XSS vulnerability in Quest Policy Authority 8.1.2.200 allowing remote attackers to inject malicious code. Find mitigation steps and prevention measures here.
Quest Policy Authority 8.1.2.200 is affected by a Stored XSS vulnerability that enables remote attackers to inject malicious code into various fields during user creation or modification.
Understanding CVE-2020-35720
This CVE involves a security issue in Quest Policy Authority 8.1.2.200 that allows the storage of malicious scripts in specific user fields.
What is CVE-2020-35720?
Stored XSS in Quest Policy Authority 8.1.2.200 permits attackers to insert harmful code into fields like first name, last name, and logon name via the submitUser.jsp file. Notably, this vulnerability impacts only products that are no longer supported by the maintainer.
The Impact of CVE-2020-35720
The vulnerability poses a risk of executing unauthorized code within the application, potentially leading to various security breaches and compromises.
Technical Details of CVE-2020-35720
Quest Policy Authority 8.1.2.200's vulnerability to Stored XSS can have severe consequences if exploited.
Vulnerability Description
The flaw allows remote attackers to store and execute malicious scripts in critical user fields, compromising the application's security.
Affected Systems and Versions
Exploitation Mechanism
Attackers can exploit this vulnerability by manipulating the user creation or modification process to inject harmful code into specific fields.
Mitigation and Prevention
It is crucial to take immediate action to address and prevent the exploitation of CVE-2020-35720.
Immediate Steps to Take
Long-Term Security Practices
Patching and Updates