ServiceNow CVE-2022-42704
ServiceNow Cross-Site Scripting
Unverified. The per-release patch levels below are an auto-import (NVD + GitHub Advisory Database) and have not yet been confirmed against the login-gated ServiceNow KB. The exposure check returns NEEDS REVIEW for this advisory — review the references and your current patch level.
Risk & exploitation
EPSS (FIRST) estimates a low likelihood of exploitation in the next 30 days (2026-06-10). Priority blends CVSS, EPSS, KEV and public-exploit availability — operational prioritization, not a NIS2/DORA reporting determination.
Summary
A cross-site scripting (XSS) vulnerability in Employee Service Center (esc) and Service Portal (sp) in ServiceNow Quebec, Rome, and San Diego allows remote attackers to inject arbitrary web script via the Standard Ticket Conversations widget.
Auto-generated stub from NVD. Detection signals and per-release fixed-in are pending manual authoring/verification; until a signal carries a verified match, the exposure check returns DORMANT/INVESTIGATE — never a false EXERCISED.Affected releases & fixed-in
| Release | Fixed in |
|---|---|
| Quebec | TODO: verify — login-gated ServiceNow KB |
| Rome | TODO: verify — login-gated ServiceNow KB |
| San Diego | TODO: verify — login-gated ServiceNow KB |
Source & attribution
GHSA GHSA-7rw7-m7rf-3h77 + NVD https://nvd.nist.gov/vuln/detail/CVE-2022-42704 (auto-synced 2026-06-08); CVSS/CWE/KEV/references from the GitHub Advisory Database (CC-BY 4.0). GHSA carries no version data — per-release fixed-in is the NVD-CPE hint or TODO: verify on the login-gated support.servicenow.com KB.
References
Data: GitHub Advisory Database (CC-BY 4.0), NVD, the CISA KEV catalog, FIRST EPSS, Exploit-DB, and Nuclei templates.