// For flags

CVE-2023-1298

 

Severity Score

6.1
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

Track
*SSVC
Descriptions

ServiceNow has released upgrades and patches that address a Reflected Cross-Site scripting (XSS) vulnerability that was identified in the ServiceNow Polaris Layout. This vulnerability would enable an authenticated user to inject arbitrary scripts.

*Credits: Osama Yousef
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Changed
Confidentiality
Low
Integrity
Low
Availability
None
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
Low
Integrity
None
Availability
None
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
Partial
Integrity
Partial
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:Track
Exploitation
None
Automatable
No
Tech. Impact
Partial
* Organization's Worst-case Scenario
Timeline
  • 2023-03-09 CVE Reserved
  • 2023-07-06 CVE Published
  • 2024-10-21 CVE Updated
  • 2025-01-26 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
  • CAPEC-63: Cross-Site Scripting (XSS)
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Servicenow
Search vendor "Servicenow"
Servicenow
Search vendor "Servicenow" for product "Servicenow"
san_diego
Search vendor "Servicenow" for product "Servicenow" and version "san_diego"
patch_1
Affected
Servicenow
Search vendor "Servicenow"
Servicenow
Search vendor "Servicenow" for product "Servicenow"
san_diego
Search vendor "Servicenow" for product "Servicenow" and version "san_diego"
patch_1_hotfix_1
Affected
Servicenow
Search vendor "Servicenow"
Servicenow
Search vendor "Servicenow" for product "Servicenow"
san_diego
Search vendor "Servicenow" for product "Servicenow" and version "san_diego"
patch_1_hotfix_1a
Affected
Servicenow
Search vendor "Servicenow"
Servicenow
Search vendor "Servicenow" for product "Servicenow"
san_diego
Search vendor "Servicenow" for product "Servicenow" and version "san_diego"
patch_1_hotfix_1b
Affected
Servicenow
Search vendor "Servicenow"
Servicenow
Search vendor "Servicenow" for product "Servicenow"
san_diego
Search vendor "Servicenow" for product "Servicenow" and version "san_diego"
patch_2
Affected
Servicenow
Search vendor "Servicenow"
Servicenow
Search vendor "Servicenow" for product "Servicenow"
san_diego
Search vendor "Servicenow" for product "Servicenow" and version "san_diego"
patch_2_hotfix_1
Affected
Servicenow
Search vendor "Servicenow"
Servicenow
Search vendor "Servicenow" for product "Servicenow"
san_diego
Search vendor "Servicenow" for product "Servicenow" and version "san_diego"
patch_3
Affected
Servicenow
Search vendor "Servicenow"
Servicenow
Search vendor "Servicenow" for product "Servicenow"
san_diego
Search vendor "Servicenow" for product "Servicenow" and version "san_diego"
patch_3_hotfix_1
Affected
Servicenow
Search vendor "Servicenow"
Servicenow
Search vendor "Servicenow" for product "Servicenow"
san_diego
Search vendor "Servicenow" for product "Servicenow" and version "san_diego"
patch_3_hotfix_2
Affected
Servicenow
Search vendor "Servicenow"
Servicenow
Search vendor "Servicenow" for product "Servicenow"
san_diego
Search vendor "Servicenow" for product "Servicenow" and version "san_diego"
patch_3_hotfix_3
Affected
Servicenow
Search vendor "Servicenow"
Servicenow
Search vendor "Servicenow" for product "Servicenow"
san_diego
Search vendor "Servicenow" for product "Servicenow" and version "san_diego"
patch_3_hotfix_4
Affected
Servicenow
Search vendor "Servicenow"
Servicenow
Search vendor "Servicenow" for product "Servicenow"
san_diego
Search vendor "Servicenow" for product "Servicenow" and version "san_diego"
patch_4
Affected
Servicenow
Search vendor "Servicenow"
Servicenow
Search vendor "Servicenow" for product "Servicenow"
san_diego
Search vendor "Servicenow" for product "Servicenow" and version "san_diego"
patch_4a
Affected
Servicenow
Search vendor "Servicenow"
Servicenow
Search vendor "Servicenow" for product "Servicenow"
san_diego
Search vendor "Servicenow" for product "Servicenow" and version "san_diego"
patch_4b
Affected
Servicenow
Search vendor "Servicenow"
Servicenow
Search vendor "Servicenow" for product "Servicenow"
san_diego
Search vendor "Servicenow" for product "Servicenow" and version "san_diego"
patch_5
Affected
Servicenow
Search vendor "Servicenow"
Servicenow
Search vendor "Servicenow" for product "Servicenow"
san_diego
Search vendor "Servicenow" for product "Servicenow" and version "san_diego"
patch_6
Affected
Servicenow
Search vendor "Servicenow"
Servicenow
Search vendor "Servicenow" for product "Servicenow"
san_diego
Search vendor "Servicenow" for product "Servicenow" and version "san_diego"
patch_7
Affected
Servicenow
Search vendor "Servicenow"
Servicenow
Search vendor "Servicenow" for product "Servicenow"
san_diego
Search vendor "Servicenow" for product "Servicenow" and version "san_diego"
patch_7_hotfix_1
Affected
Servicenow
Search vendor "Servicenow"
Servicenow
Search vendor "Servicenow" for product "Servicenow"
san_diego
Search vendor "Servicenow" for product "Servicenow" and version "san_diego"
patch_7_hotfix_2
Affected
Servicenow
Search vendor "Servicenow"
Servicenow
Search vendor "Servicenow" for product "Servicenow"
san_diego
Search vendor "Servicenow" for product "Servicenow" and version "san_diego"
patch_7_hottix_3
Affected
Servicenow
Search vendor "Servicenow"
Servicenow
Search vendor "Servicenow" for product "Servicenow"
san_diego
Search vendor "Servicenow" for product "Servicenow" and version "san_diego"
patch_7a
Affected
Servicenow
Search vendor "Servicenow"
Servicenow
Search vendor "Servicenow" for product "Servicenow"
san_diego
Search vendor "Servicenow" for product "Servicenow" and version "san_diego"
patch_7b
Affected
Servicenow
Search vendor "Servicenow"
Servicenow
Search vendor "Servicenow" for product "Servicenow"
san_diego
Search vendor "Servicenow" for product "Servicenow" and version "san_diego"
patch_8
Affected
Servicenow
Search vendor "Servicenow"
Servicenow
Search vendor "Servicenow" for product "Servicenow"
san_diego
Search vendor "Servicenow" for product "Servicenow" and version "san_diego"
patch_8_hotfix_1
Affected
Servicenow
Search vendor "Servicenow"
Servicenow
Search vendor "Servicenow" for product "Servicenow"
san_diego
Search vendor "Servicenow" for product "Servicenow" and version "san_diego"
patch_8_hotfix_2
Affected
Servicenow
Search vendor "Servicenow"
Servicenow
Search vendor "Servicenow" for product "Servicenow"
san_diego
Search vendor "Servicenow" for product "Servicenow" and version "san_diego"
patch_9
Affected
Servicenow
Search vendor "Servicenow"
Servicenow
Search vendor "Servicenow" for product "Servicenow"
san_diego
Search vendor "Servicenow" for product "Servicenow" and version "san_diego"
patch_9a
Affected
Servicenow
Search vendor "Servicenow"
Servicenow
Search vendor "Servicenow" for product "Servicenow"
san_diego
Search vendor "Servicenow" for product "Servicenow" and version "san_diego"
patch_9a_hotfix_1
Affected
Servicenow
Search vendor "Servicenow"
Servicenow
Search vendor "Servicenow" for product "Servicenow"
san_diego
Search vendor "Servicenow" for product "Servicenow" and version "san_diego"
patch_9b
Affected
Servicenow
Search vendor "Servicenow"
Servicenow
Search vendor "Servicenow" for product "Servicenow"
tokyo
Search vendor "Servicenow" for product "Servicenow" and version "tokyo"
-
Affected
Servicenow
Search vendor "Servicenow"
Servicenow
Search vendor "Servicenow" for product "Servicenow"
tokyo
Search vendor "Servicenow" for product "Servicenow" and version "tokyo"
patch_1
Affected
Servicenow
Search vendor "Servicenow"
Servicenow
Search vendor "Servicenow" for product "Servicenow"
tokyo
Search vendor "Servicenow" for product "Servicenow" and version "tokyo"
patch_1_hotfix_1
Affected
Servicenow
Search vendor "Servicenow"
Servicenow
Search vendor "Servicenow" for product "Servicenow"
tokyo
Search vendor "Servicenow" for product "Servicenow" and version "tokyo"
patch_1a
Affected
Servicenow
Search vendor "Servicenow"
Servicenow
Search vendor "Servicenow" for product "Servicenow"
tokyo
Search vendor "Servicenow" for product "Servicenow" and version "tokyo"
patch_1b
Affected
Servicenow
Search vendor "Servicenow"
Servicenow
Search vendor "Servicenow" for product "Servicenow"
tokyo
Search vendor "Servicenow" for product "Servicenow" and version "tokyo"
patch_2
Affected
Servicenow
Search vendor "Servicenow"
Servicenow
Search vendor "Servicenow" for product "Servicenow"
tokyo
Search vendor "Servicenow" for product "Servicenow" and version "tokyo"
patch_2_hotfix_1
Affected
Servicenow
Search vendor "Servicenow"
Servicenow
Search vendor "Servicenow" for product "Servicenow"
tokyo
Search vendor "Servicenow" for product "Servicenow" and version "tokyo"
patch_2_hotfix_2
Affected
Servicenow
Search vendor "Servicenow"
Servicenow
Search vendor "Servicenow" for product "Servicenow"
tokyo
Search vendor "Servicenow" for product "Servicenow" and version "tokyo"
patch_2_hotfix_3
Affected
Servicenow
Search vendor "Servicenow"
Servicenow
Search vendor "Servicenow" for product "Servicenow"
tokyo
Search vendor "Servicenow" for product "Servicenow" and version "tokyo"
patch_2_hotfix_4
Affected
Servicenow
Search vendor "Servicenow"
Servicenow
Search vendor "Servicenow" for product "Servicenow"
tokyo
Search vendor "Servicenow" for product "Servicenow" and version "tokyo"
patch_3
Affected
Servicenow
Search vendor "Servicenow"
Servicenow
Search vendor "Servicenow" for product "Servicenow"
tokyo
Search vendor "Servicenow" for product "Servicenow" and version "tokyo"
patch_3_hotfix_1
Affected
Servicenow
Search vendor "Servicenow"
Servicenow
Search vendor "Servicenow" for product "Servicenow"
tokyo
Search vendor "Servicenow" for product "Servicenow" and version "tokyo"
patch_3_hotfix_2
Affected
Servicenow
Search vendor "Servicenow"
Servicenow
Search vendor "Servicenow" for product "Servicenow"
tokyo
Search vendor "Servicenow" for product "Servicenow" and version "tokyo"
patch_3_hotfix_3
Affected
Servicenow
Search vendor "Servicenow"
Servicenow
Search vendor "Servicenow" for product "Servicenow"
tokyo
Search vendor "Servicenow" for product "Servicenow" and version "tokyo"
patch_3_hotfix_4
Affected
Servicenow
Search vendor "Servicenow"
Servicenow
Search vendor "Servicenow" for product "Servicenow"
tokyo
Search vendor "Servicenow" for product "Servicenow" and version "tokyo"
patch_4
Affected
Servicenow
Search vendor "Servicenow"
Servicenow
Search vendor "Servicenow" for product "Servicenow"
tokyo
Search vendor "Servicenow" for product "Servicenow" and version "tokyo"
patch_4_hotfix_2
Affected
Servicenow
Search vendor "Servicenow"
Servicenow
Search vendor "Servicenow" for product "Servicenow"
tokyo
Search vendor "Servicenow" for product "Servicenow" and version "tokyo"
patch_4_hotfix_3
Affected
Servicenow
Search vendor "Servicenow"
Servicenow
Search vendor "Servicenow" for product "Servicenow"
tokyo
Search vendor "Servicenow" for product "Servicenow" and version "tokyo"
patch_4a
Affected
Servicenow
Search vendor "Servicenow"
Servicenow
Search vendor "Servicenow" for product "Servicenow"
tokyo
Search vendor "Servicenow" for product "Servicenow" and version "tokyo"
patch_4a_hotfix_1
Affected
Servicenow
Search vendor "Servicenow"
Servicenow
Search vendor "Servicenow" for product "Servicenow"
tokyo
Search vendor "Servicenow" for product "Servicenow" and version "tokyo"
patch_5
Affected
Servicenow
Search vendor "Servicenow"
Servicenow
Search vendor "Servicenow" for product "Servicenow"
tokyo
Search vendor "Servicenow" for product "Servicenow" and version "tokyo"
patch_5_hotfix_1
Affected
Servicenow
Search vendor "Servicenow"
Servicenow
Search vendor "Servicenow" for product "Servicenow"
tokyo
Search vendor "Servicenow" for product "Servicenow" and version "tokyo"
patch_5_hotfix_2
Affected
Servicenow
Search vendor "Servicenow"
Servicenow
Search vendor "Servicenow" for product "Servicenow"
tokyo
Search vendor "Servicenow" for product "Servicenow" and version "tokyo"
patch_5_hotfix_3
Affected
Servicenow
Search vendor "Servicenow"
Servicenow
Search vendor "Servicenow" for product "Servicenow"
utah
Search vendor "Servicenow" for product "Servicenow" and version "utah"
patch1
Affected