Stored XSS Vulnerability in ServiceNow IT Service Management Products
CVE-2019-20768
5.4MEDIUM
What is CVE-2019-20768?
ServiceNow IT Service Management products, specifically Kingston through Patch 14-1, London through Patch 7, and Madrid before Patch 4, are susceptible to a stored XSS vulnerability. This flaw occurs via the manipulation of sysparm_item_guid and sys_id parameters within an Incident Request to service_catalog.do. Attackers can exploit this vulnerability to execute arbitrary scripts in the context of users' browsers, potentially compromising sensitive data and user sessions.