CVE-2018-8720: XSS
ServiceNow ITSM 2016-06-02 has XSS via the First Name or Last Name field of My Profile (aka navpage.do), or the Search bar of My Portal (aka searchresults.do).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-8720?
CVE-2018-8720 has a medium severity rating due to the potential for cross-site scripting attacks.
How do I fix CVE-2018-8720?
To fix CVE-2018-8720, ensure that input fields, such as First Name and Last Name on My Profile, are properly validated and sanitized.
Which versions of ServiceNow are affected by CVE-2018-8720?
CVE-2018-8720 affects ServiceNow ITSM version released on 2016-06-02 and potentially other versions if they haven't been patched.
What are the potential impacts of CVE-2018-8720?
The potential impacts of CVE-2018-8720 include unauthorized script execution, which can lead to data theft or session hijacking.
Is there a known exploit for CVE-2018-8720?
Yes, CVE-2018-8720 can be exploited through the vulnerable fields, allowing attackers to execute malicious scripts.