Record summary

CVE-2022-38463 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.

Description

ServiceNow through San Diego Patch 4b and Patch 6 allows reflected XSS in the logout functionality.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Nuclei templates

1
ProjectDiscoveryMEDIUMServiceNow - Cross-Site ScriptingCVSS 6.1

ServiceNow through San Diego Patch 4b and Patch 6 contains a cross-site scripting vulnerability in the logout functionality, which can enable an unauthenticated remote attacker to execute arbitrary JavaScript.

Impact

Successful exploitation of this vulnerability could allow an attacker to execute arbitrary JavaScript code in the context of the victim's browser, leading to session hijacking, data theft, or defacement of the affected ServiceNow instance.

Remediation

Apply the latest security patches provided by ServiceNow to mitigate this vulnerability.

WeaknessesCWE-79
Authorsamanrawat
Template tagscvecve2022servicenowxssvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:servicenow:servicenow:san_diego:patch_4:*:*:*:*:*:*
Shodan: http.title:"ServiceNow"
Shodan: http.title:"servicenow"
Shodan: http.favicon.hash:1701804003
FOFA: title="servicenow"
FOFA: icon_hash=1701804003
Google: intitle:"servicenow"

Source: ProjectDiscovery

References

2