Unrated severityNVD Advisory· Published May 5, 2020· Updated Aug 5, 2024
CVE-2019-20768
CVE-2019-20768
Description
ServiceNow IT Service Management Kingston through Patch 14-1, London through Patch 7, and Madrid before patch 4 allow stored XSS via crafted sysparm_item_guid and sys_id parameters in an Incident Request to service_catalog.do.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- ServiceNow/IT Service Managementdescription
- Range: Kingston through Patch 14-1, London through Patch 7, Madrid before patch 4
Patches
Vulnerability mechanics
References
2- outpost24.com/blog/Responsible-disclosure-Multiple-stored-XSS-vulnerabilities-discovered-in-ServiceNow-ITSMmitrex_refsource_MISC
- outpost24.com/blogmitrex_refsource_MISC
News mentions
0No linked articles in our index yet.