Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2022-39048: Knowledge Article View - Now Support Portal

A XSS vulnerability was identified in the ServiceNow UI page assessment_redirect. To exploit this vulnerability, an attacker would need to persuade an authenticated user to click a maliciously crafted URL. Successful exploitation potentially could be used to conduct various client-side attacks, including, but not limited to, phishing, redirection, theft of CSRF tokens, and use of an authenticated user’s browser or session to attack other systems.

CVE
#xss#csrf#vulnerability#auth

Loading…

Skip to page content

Skip to page content

Related news

CVE-2022-39048: ServiceNow - Now Support

ServiceNow Tokyo allows XSS.

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda