漏洞描述 ServiceNow是一种基于云计算的服务管理平台,主要用于IT服务管理,业务管理和运营管理。ServiceNow的Jelly模板由于输入验证不严格,存在注入漏洞。这些漏洞可以被未经身份验证的攻击者通过构造恶意请求利用,在ServiceNow中远程执行代码。
相关漏洞推荐 POC CVE-2021-21402: Jellyfin <10.7.0 - Local File Inclusion POC CVE-2021-29490: Jellyfin 10.7.2 - Server Side Request Forgery POC CVE-2022-38463: ServiceNow - Cross-Site Scripting POC CVE-2022-39048: ServiceNow - Cross-site Scripting POC CVE-2024-4879: ServiceNow UI Macros - Template Injection POC CVE-2024-5217: ServiceNow - Incomplete Input Validation POC CVE-2021-21402: Jellyfin prior to 10.7.0 Unauthenticated Arbitrary File Read POC servicenow-kbcprod-csp-bypass: Content-Security-Policy Bypass - ServiceNow KBCProd POC jellyfin-default-login: Jellyfin Console - Default Login POC servicenow-widget-misconfig: ServiceNow Widget-Simple-List - Misconfiguration POC servicenow-helpdesk-credential: ServiceNow Helpdesk Credential Exposure ServiceNow Now Platform 未授权 代码注入漏洞 ServiceNow CVE-2024-4879 Jelly模板注入漏洞