NA

CVE-2022-46389

Published: 17/04/2023 Updated: 27/04/2023
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

There exists a reflected XSS within the logout functionality of ServiceNow versions lower than Quebec Patch 10 Hotfix 11b, Rome Patch 10 Hotfix 3b, San Diego Patch 9, Tokyo Patch 4, and Utah GA. This enables an unauthenticated remote malicious user to execute arbitrary JavaScript code in the browser-based web console.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

servicenow servicenow san_diego

servicenow servicenow rome

servicenow servicenow quebec

servicenow servicenow utah

servicenow servicenow tokyo