There exists a reflected XSS within the logout functionality of ServiceNow versions lower than Quebec Patch 10 Hotfix 11b, Rome Patch 10 Hotfix 3b, San Diego Patch 9, Tokyo Patch 4, and Utah GA. This enables an unauthenticated remote attacker to execute arbitrary JavaScript code in the browser-based web console.
History

Thu, 06 Feb 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: SN

Published:

Updated: 2025-02-06T16:01:59.247Z

Reserved: 2022-12-04T00:00:00.000Z

Link: CVE-2022-46389

cve-icon Vulnrichment

Updated: 2024-08-03T14:31:46.337Z

cve-icon NVD

Status : Modified

Published: 2023-04-17T22:15:07.840

Modified: 2024-11-21T07:30:30.130

Link: CVE-2022-46389

cve-icon Redhat

No data.