PT-2023-13678 · Servicenow · Servicenow

·

CVE-2022-39048

·

Published

2023-04-10

·

Updated

2025-02-07

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions ServiceNow (affected versions not specified)
Description A XSS issue was identified in the ServiceNow UI page assessment redirect. To exploit this, an attacker would need to persuade an authenticated user to click a maliciously crafted URL. Successful exploitation could be used to conduct various client-side attacks, including phishing, redirection, theft of CSRF tokens, and use of an authenticated user's browser or session to attack other systems.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-39048

Affected Products

Servicenow