XSS in ServiceNow logout https://████:443

Disclosed: 2023-05-15 15:14:43 By colemanj To deptofdefense
Medium
Vulnerability Details
**Description:** XSS in ServiceNow logout https://██████:443/logout_redirect.do?sysparm_url=//j%5c%5cjavascript%3aalert(document.domain) ## References https://nvd.nist.gov/vuln/detail/CVE-2022-38463 ## Impact Unauthenticated remote attacker can execute code in user's browser context. User must click on malicious link ## System Host(s) ███████ ## Affected Product(s) and Version(s) Servicenow prior to SanDiego SP6 ## CVE Numbers CVE-2022-38463 ## Steps to Reproduce Click on https://█████:443/logout_redirect.do?sysparm_url=//j%5c%5cjavascript%3aalert(document.domain) ## Suggested Mitigation/Remediation Actions Upgrade to patched version of ServiceNow
Actions
View on HackerOne
Report Stats
  • Report ID: 1699855
  • State: Closed
  • Substate: resolved
  • Upvotes: 5
Share this report