Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-48vw-436h-p87m

Опубликовано: 10 апр. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 6.1

Описание

ServiceNow Tokyo allows XSS.

ServiceNow Tokyo allows XSS.

EPSS

Процентиль: 95%
0.20219
Средний

6.1 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.1
nvd
почти 3 года назад

A XSS vulnerability was identified in the ServiceNow UI page assessment_redirect. To exploit this vulnerability, an attacker would need to persuade an authenticated user to click a maliciously crafted URL. Successful exploitation potentially could be used to conduct various client-side attacks, including, but not limited to, phishing, redirection, theft of CSRF tokens, and use of an authenticated user's browser or session to attack other systems.

EPSS

Процентиль: 95%
0.20219
Средний

6.1 Medium

CVSS3

Дефекты

CWE-79