CVE-2018-7748

Publication date

2018-08-03 18:00:00

Family

mitre

State

PUBLISHED

Description

report_viewer.do in ServiceNow Release Jakarta Patch 8 and earlier allows remote attackers to execute arbitrary code via ${xyz} Glide Scripting Injection in the sysparm_media parameter.