ZeroHour

CVE-2020-35205

PoC ×2
CVSS 3.1
9.8 critical
EPSS
2%p79
Published
()
Modified
Description

Server Side Request Forgery (SSRF) in Web Compliance Manager in Quest Policy Authority version 8.1.2.200 allows attackers to scan internal ports and make outbound connections via the initFile.jsp file. NOTE: This vulnerability only affects products that are no longer supported by the maintainer

Vendors
quest
Products
policy authority for unified communications
Weakness
CWE-918
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.