ServiceNow AI Platform是美国ServiceNow公司的一款AI智能平台。 ServiceNow AI Platform存在安全漏洞,该漏洞源于反射型跨站脚本漏洞,可能导致用户点击特制链接时在浏览器中执行任意代码。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| ServiceNow | ServiceNow AI Platform | 0 ~ Washington DC Patch 10 Hot Fix 7b | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | This script automatically detects and remediates **CVE-2025-11449** and **CVE-2025-11450** security vulnerabilities in ServiceNow UI Macros. These critical vulnerabilities could allow arbitrary code execution in users' browsers through specially crafted links if user-controlled `sysparm_` parameters are not properly sanitized. | https://github.com/DanielMadsenDK/ServiceNow-CVE-2025-11449-CVE-2025-11450-Mitigation-Script | POC Details |
No public POC found.
Login to generate AI POCNo comments yet