There exists a reflected XSS within the logout functionality of ServiceNow versions lower than Quebec Patch 10 Hotfix 11b, Rome Patch 10 Hotfix 3b, San Diego Patch 9, Tokyo Patch 4, and Utah GA. This enables an unauthenticated remote attacker to execute arbitrary JavaScript code in the browser-based web console.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: SN

Published: 2023-04-17T00:00:00

Updated: 2024-08-03T14:31:46.337Z

Reserved: 2022-12-04T00:00:00

Link: CVE-2022-46389

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2023-04-17T22:15:07.840

Modified: 2023-04-27T19:50:22.780

Link: CVE-2022-46389

cve-icon Redhat

No data.