CVE-2019-20768

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
05/05/2020
Last modified:
12/05/2020

Description

ServiceNow IT Service Management Kingston through Patch 14-1, London through Patch 7, and Madrid before patch 4 allow stored XSS via crafted sysparm_item_guid and sys_id parameters in an Incident Request to service_catalog.do.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:servicenow:it_service_management:kingston:-:*:*:*:*:*:*
cpe:2.3:a:servicenow:it_service_management:kingston:patch_1:*:*:*:*:*:*
cpe:2.3:a:servicenow:it_service_management:kingston:patch_10:*:*:*:*:*:*
cpe:2.3:a:servicenow:it_service_management:kingston:patch_10-1:*:*:*:*:*:*
cpe:2.3:a:servicenow:it_service_management:kingston:patch_10-2:*:*:*:*:*:*
cpe:2.3:a:servicenow:it_service_management:kingston:patch_11:*:*:*:*:*:*
cpe:2.3:a:servicenow:it_service_management:kingston:patch_12:*:*:*:*:*:*
cpe:2.3:a:servicenow:it_service_management:kingston:patch_12-1:*:*:*:*:*:*
cpe:2.3:a:servicenow:it_service_management:kingston:patch_12-2:*:*:*:*:*:*
cpe:2.3:a:servicenow:it_service_management:kingston:patch_13:*:*:*:*:*:*
cpe:2.3:a:servicenow:it_service_management:kingston:patch_14:*:*:*:*:*:*
cpe:2.3:a:servicenow:it_service_management:kingston:patch_14-1:*:*:*:*:*:*
cpe:2.3:a:servicenow:it_service_management:kingston:patch_2:*:*:*:*:*:*
cpe:2.3:a:servicenow:it_service_management:kingston:patch_3:*:*:*:*:*:*
cpe:2.3:a:servicenow:it_service_management:kingston:patch_3-1:*:*:*:*:*:*