CVE-2024-5890: HTML Injection in the Assessment plugin
ServiceNow has addressed an HTML injection vulnerability that was identified in the Now Platform. This vulnerability could potentially enable an unauthenticated user to modify a web page or redirect users to another website.
ServiceNow released updates to customers that addressed this vulnerability. If you have not done so already, we recommend applying security patches relevant to your instance(s) as soon as possible.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-5890?
CVE-2024-5890 has a moderate severity rating due to its potential to allow unauthenticated users to modify web pages.
How do I fix CVE-2024-5890?
To fix CVE-2024-5890, ensure your ServiceNow Now Platform is updated to the latest version as released by ServiceNow.
What impact does CVE-2024-5890 have on users?
CVE-2024-5890 could allow attackers to redirect users or alter the content of web pages, impacting user trust and security.
Is CVE-2024-5890 remote exploitable?
Yes, CVE-2024-5890 is remote exploitable, allowing unauthenticated users to attack the vulnerability without local access.
What versions of the Now Platform are affected by CVE-2024-5890?
CVE-2024-5890 affects certain versions of the ServiceNow Now Platform prior to the release of the security updates.