ServiceNow CVE-2023-1298
ServiceNow Cross-Site Scripting
Risk & exploitation
EPSS (FIRST) estimates a low-to-moderate likelihood of exploitation in the next 30 days (2026-06-10). Priority blends CVSS, EPSS, KEV and public-exploit availability — operational prioritization, not a NIS2/DORA reporting determination.
Summary
ServiceNow has released upgrades and patches that address a Reflected Cross-Site scripting (XSS) vulnerability that was identified in the ServiceNow Polaris Layout. This vulnerability would enable an authenticated user to inject arbitrary scripts.
Auto-generated stub from NVD. Detection signals and per-release fixed-in are pending manual authoring/verification; until a signal carries a verified match, the exposure check returns DORMANT/INVESTIGATE — never a false EXERCISED.Affected releases & fixed-in
| Release | Fixed in |
|---|---|
| Utah | Patch 1 |
| Tokyo | Patch 4b / Patch 6 |
| San Diego | Patch 10 |
Source & attribution
Per-release fixed-in VERIFIED against the ServiceNow-authored CVE Record (CNA shortName: SN) — affected[].versions[] boundaries, https://cveawg.mitre.org/api/cve/CVE-2023-1298 (retrieved 2026-06-08). The same patch matrix is in the login-gated ServiceNow KB; the public CVE Record is the citable source.
References
Data: GitHub Advisory Database (CC-BY 4.0), NVD, the CISA KEV catalog, FIRST EPSS, Exploit-DB, and Nuclei templates.