CVE-2022-42704: XSS
A cross-site scripting (XSS) vulnerability in Employee Service Center (esc) and Service Portal (sp) in ServiceNow Quebec, Rome, and San Diego allows remote attackers to inject arbitrary web script via the Standard Ticket Conversations widget.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2022-42704?
CVE-2022-42704 is a cross-site scripting (XSS) vulnerability in Employee Service Center (esc) and Service Portal (sp) in ServiceNow Quebec, Rome, and San Diego.
How does CVE-2022-42704 impact ServiceNow?
CVE-2022-42704 allows remote attackers to inject arbitrary web script via the Standard Ticket Conversations widget.
Which versions of ServiceNow are affected by CVE-2022-42704?
CVE-2022-42704 affects ServiceNow versions Quebec, Rome, and San Diego.
What is the severity of CVE-2022-42704?
CVE-2022-42704 has a severity rating of medium with a CVSS score of 5.4.
How can I fix the CVE-2022-42704 vulnerability?
To fix the CVE-2022-42704 vulnerability, apply the necessary patches provided by ServiceNow and follow their recommendations.