← All CVEs & advisories

ServiceNow CVE-2022-39048

ServiceNow Cross-Site Scripting

XSSCVSS 3.1 6.1Priority 33Disclosed 2023-04-10Unverified

Unverified. The per-release patch levels below are an auto-import (NVD + GitHub Advisory Database) and have not yet been confirmed against the login-gated ServiceNow KB. The exposure check returns NEEDS REVIEW for this advisory — review the references and your current patch level.

Risk & exploitation

PriorityMedium · 33/100
EPSS0.170 · 95.1th pct
CISA KEVNo
Public exploitYes — nuclei

EPSS (FIRST) estimates a elevated likelihood of exploitation in the next 30 days (2026-06-10). Priority blends CVSS, EPSS, KEV and public-exploit availability — operational prioritization, not a NIS2/DORA reporting determination.

Summary

A XSS vulnerability was identified in the ServiceNow UI page assessment_redirect. To exploit this vulnerability, an attacker would need to persuade an authenticated user to click a maliciously crafted URL. Successful exploitation potentially could be used to conduct various client-side attacks, including, but not limited to, phishing, redirection, theft of CSRF tokens, and use of an authenticated user's browser or session to attack other systems.

Auto-generated stub from NVD. Detection signals and per-release fixed-in are pending manual authoring/verification; until a signal carries a verified match, the exposure check returns DORMANT/INVESTIGATE — never a false EXERCISED.

Affected releases & fixed-in

ReleaseFixed in
QuebecTODO: verify — login-gated ServiceNow KB
RomeTODO: verify — login-gated ServiceNow KB
San DiegoTODO: verify — login-gated ServiceNow KB
TokyoTODO: verify — login-gated ServiceNow KB
UtahTODO: verify — login-gated ServiceNow KB
Source & attribution

GHSA GHSA-48vw-436h-p87m + NVD https://nvd.nist.gov/vuln/detail/CVE-2022-39048 (auto-synced 2026-06-08); CVSS/CWE/KEV/references from the GitHub Advisory Database (CC-BY 4.0). GHSA carries no version data — per-release fixed-in is the NVD-CPE hint or TODO: verify on the login-gated support.servicenow.com KB.

Check your instance for CVE-2022-39048

References

Data: GitHub Advisory Database (CC-BY 4.0), NVD, the CISA KEV catalog, FIRST EPSS, Exploit-DB, and Nuclei templates.