This CPE summary could be partial or incomplete. Please contact us for a detailed listing.

Summary

Detail
Vendor Servicenow First view 2023-07-06
Product Servicenow Last view 2023-07-06
Version tokyo Type Application
Update patch_4a_hotfix_1  
Edition *  
Language *  
Sofware Edition *  
Target Software *  
Target Hardware *  
Other *  
 
CPE Product cpe:2.3:a:servicenow:servicenow

Activity : Overall

Related : CVE

  Date Alert Description
6.1 2023-07-06 CVE-2023-1298

ServiceNow has released upgrades and patches that address a Reflected Cross-Site scripting (XSS) vulnerability that was identified in the ServiceNow Polaris Layout. This vulnerability would enable an authenticated user to inject arbitrary scripts.

CWE : Common Weakness Enumeration

%idName
100% (1) CWE-79 Failure to Preserve Web Page Structure ('Cross-site Scripting')