CVE-2018-7748: ServiceNow
High severity, CVSS 8.8. EPSS: 2.6% chance of exploitation in the next 30 days.
report_viewer.do in ServiceNow Release Jakarta Patch 8 and earlier allows remote attackers to execute arbitrary code via '${xyz}' Glide Scripting Injection in the sysparm_media parameter.
Affected products
- ServiceNow ServiceNow: version jakarta only
Published 2018-08-03. Last modified 2026-06-17.