Unrated severityNVD Advisory· Published Apr 10, 2023· Updated Feb 7, 2025
Cross-Site Scripting (XSS) vulnerability in ServiceNow UI page assessment_redirect
CVE-2022-39048
Description
A XSS vulnerability was identified in the ServiceNow UI page assessment_redirect. To exploit this vulnerability, an attacker would need to persuade an authenticated user to click a maliciously crafted URL. Successful exploitation potentially could be used to conduct various client-side attacks, including, but not limited to, phishing, redirection, theft of CSRF tokens, and use of an authenticated user's browser or session to attack other systems.
Affected products
1- Range: Tokyo
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2News mentions
0No linked articles in our index yet.