A XSS vulnerability was identified in the ServiceNow UI page assessment_redirect. To exploit this vulnerability, an attacker would need to persuade an authenticated user to click a maliciously crafted URL. Successful exploitation potentially could be used to conduct various client-side attacks, including, but not limited to, phishing, redirection, theft of CSRF tokens, and use of an authenticated user's browser or session to attack other systems.
History

Fri, 07 Feb 2025 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: SN

Published:

Updated: 2025-02-07T20:14:00.361Z

Reserved: 2022-08-31T00:00:00.000Z

Link: CVE-2022-39048

cve-icon Vulnrichment

Updated: 2024-08-03T11:10:32.338Z

cve-icon NVD

Status : Modified

Published: 2023-04-10T14:15:07.453

Modified: 2025-02-07T21:15:09.980

Link: CVE-2022-39048

cve-icon Redhat

No data.