#VU71120 Code Injection in ServiceNow - CVE-2018-7748
Published: January 12, 2023
ServiceNow
ServiceNow
Description
The vulnerability allows a remote user to execute arbitrary code on the target system.
The vulnerability exists due to improper input validation when processing data passed via the "sysparm_media" parameter to "/report_viewer.do" endpoint. A remote user can send a specially crafted HTTP request and execute arbitrary code on the target system.