CVE-2023-1298: ServiceNow

Medium severity, CVSS 6.1. EPSS: 0.4% chance of exploitation in the next 30 days.

ServiceNow has released upgrades and patches that address a Reflected Cross-Site scripting (XSS) vulnerability that was identified in the ServiceNow Polaris Layout. This vulnerability would enable an authenticated user to inject arbitrary scripts.

Affected products

  • ServiceNow ServiceNow: version san_diego only; version tokyo only; version utah only

Published 2023-07-06. Last modified 2026-06-17.