Medium severity5.4NVD Advisory· Published Jan 13, 2023· Updated Jun 17, 2026
CVE-2022-42704
CVE-2022-42704
Description
A cross-site scripting (XSS) vulnerability in Employee Service Center (esc) and Service Portal (sp) in ServiceNow Quebec, Rome, and San Diego allows remote attackers to inject arbitrary web script via the Standard Ticket Conversations widget.
Affected products
10cpe:2.3:a:servicenow:servicenow:quebec:*:*:*:*:*:*:*+ 7 more
- cpe:2.3:a:servicenow:servicenow:quebec:*:*:*:*:*:*:*
- cpe:2.3:a:servicenow:servicenow:rome:*:*:*:*:*:*:*
- cpe:2.3:a:servicenow:servicenow:rome:patch_1:*:*:*:*:*:*
- cpe:2.3:a:servicenow:servicenow:rome:patch_2:*:*:*:*:*:*
- cpe:2.3:a:servicenow:servicenow:rome:patch_3:*:*:*:*:*:*
- cpe:2.3:a:servicenow:servicenow:rome:patch_4:*:*:*:*:*:*
- cpe:2.3:a:servicenow:servicenow:san_diego:*:*:*:*:*:*:*
- (no CPE)
Patches
Vulnerability mechanics
References
1- support.servicenow.com/kbnvdPatchVendor Advisory
News mentions
0No linked articles in our index yet.