Логотип exploitDog
bind:CVE-2022-39048
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2022-39048

Количество 2

Количество 2

nvd логотип

CVE-2022-39048

почти 3 года назад

A XSS vulnerability was identified in the ServiceNow UI page assessment_redirect. To exploit this vulnerability, an attacker would need to persuade an authenticated user to click a maliciously crafted URL. Successful exploitation potentially could be used to conduct various client-side attacks, including, but not limited to, phishing, redirection, theft of CSRF tokens, and use of an authenticated user's browser or session to attack other systems.

CVSS3: 6.1
EPSS: Средний
github логотип

GHSA-48vw-436h-p87m

почти 3 года назад

ServiceNow Tokyo allows XSS.

CVSS3: 6.1
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2022-39048

A XSS vulnerability was identified in the ServiceNow UI page assessment_redirect. To exploit this vulnerability, an attacker would need to persuade an authenticated user to click a maliciously crafted URL. Successful exploitation potentially could be used to conduct various client-side attacks, including, but not limited to, phishing, redirection, theft of CSRF tokens, and use of an authenticated user's browser or session to attack other systems.

CVSS3: 6.1
20%
Средний
почти 3 года назад
github логотип
GHSA-48vw-436h-p87m

ServiceNow Tokyo allows XSS.

CVSS3: 6.1
20%
Средний
почти 3 года назад

Уязвимостей на страницу