← All CVEs & advisories

ServiceNow CVE-2022-42704

ServiceNow Cross-Site Scripting

XSSCVSS 3.1 5.4Priority 11Disclosed 2023-01-13Unverified

Unverified. The per-release patch levels below are an auto-import (NVD + GitHub Advisory Database) and have not yet been confirmed against the login-gated ServiceNow KB. The exposure check returns NEEDS REVIEW for this advisory — review the references and your current patch level.

Risk & exploitation

PriorityLow · 11/100
EPSS0.002 · 44.2th pct
CISA KEVNo
Public exploitNone indexed

EPSS (FIRST) estimates a low likelihood of exploitation in the next 30 days (2026-06-10). Priority blends CVSS, EPSS, KEV and public-exploit availability — operational prioritization, not a NIS2/DORA reporting determination.

Summary

A cross-site scripting (XSS) vulnerability in Employee Service Center (esc) and Service Portal (sp) in ServiceNow Quebec, Rome, and San Diego allows remote attackers to inject arbitrary web script via the Standard Ticket Conversations widget.

Auto-generated stub from NVD. Detection signals and per-release fixed-in are pending manual authoring/verification; until a signal carries a verified match, the exposure check returns DORMANT/INVESTIGATE — never a false EXERCISED.

Affected releases & fixed-in

ReleaseFixed in
QuebecTODO: verify — login-gated ServiceNow KB
RomeTODO: verify — login-gated ServiceNow KB
San DiegoTODO: verify — login-gated ServiceNow KB
Source & attribution

GHSA GHSA-7rw7-m7rf-3h77 + NVD https://nvd.nist.gov/vuln/detail/CVE-2022-42704 (auto-synced 2026-06-08); CVSS/CWE/KEV/references from the GitHub Advisory Database (CC-BY 4.0). GHSA carries no version data — per-release fixed-in is the NVD-CPE hint or TODO: verify on the login-gated support.servicenow.com KB.

Check your instance for CVE-2022-42704

References

Data: GitHub Advisory Database (CC-BY 4.0), NVD, the CISA KEV catalog, FIRST EPSS, Exploit-DB, and Nuclei templates.