CyberRota Analysis
This is a medium severity vulnerability with a CVSS score of 5.4. It may be remotely exploitable.
CVE
CVE-2022-42704
Severity
MEDIUM
CVSS
5.4
EPSS
0.44%
Original NVD Description
A cross-site scripting (XSS) vulnerability in Employee Service Center (esc) and Service Portal (sp) in ServiceNow Quebec, Rome, and San Diego allows remote attackers to inject arbitrary web script via the Standard Ticket Conversations widget.
Related CVEs
Other vulnerabilities affecting the same vendor(s)