CVE-2019-20768: ServiceNow It Service Management

Medium severity, CVSS 5.4. EPSS: 0.7% chance of exploitation in the next 30 days.

ServiceNow IT Service Management Kingston through Patch 14-1, London through Patch 7, and Madrid before patch 4 allow stored XSS via crafted sysparm_item_guid and sys_id parameters in an Incident Request to service_catalog.do.

Affected products

  • ServiceNow It Service Management: version kingston only; version london only; version madrid only

Published 2020-05-05. Last modified 2026-06-17.