PT-2024-37225 · Servicenow · Servicenow

Published

2024-12-02

·

Updated

2024-12-02

·

CVE-2024-5890

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions: ServiceNow (affected versions not specified)
Description: The issue is related to an HTML injection vulnerability identified in the Now Platform. This could potentially enable an unauthenticated user to modify a web page or redirect users to another website. ServiceNow has released updates to address this issue.
Recommendations: Apply the relevant security patches to your instance(s) as soon as possible. As a temporary workaround, consider restricting access to potentially vulnerable web pages until a patch is applied. If you have not done so already, update your instance with the latest security updates provided by ServiceNow.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-5890

Affected Products

Servicenow