CVE ID : CVE-2023-23073
Product Name | Severity | Affected Version(s) | Fixed Version | Fixed On |
---|---|---|---|---|
ServiceDesk Plus | Medium | 14102 and below | 14103 | Dec. 23, 2022 |
ServiceDesk Plus MSP | Medium | 13001 and below | 13002 | Dec. 14, 2022 |
Details
A stored cross-site scripting (XSS) vulnerability allowed any low-privileged user to inject malicious JavaScript when associating a service request from the purchase order details page. The JavaScript is executed when the target user views the Associate Service Requests list view in the Purchase Order details page.
We fixed the issue by encoding data during client rendering to prevent the JavaScript from being executed.
Impact
The vulnerability can be exploited by threat actors to perform further attacks.
Steps to upgrade
Acknowledgements
This vulnerability was reported by HMs on our bug bounty portal.
If you have any questions or concerns, please contact product support for further details at the below-mentioned email addresses.
ServiceDesk Plus: support@servicedeskplus.com
ServiceDesk Plus MSP: support@servicedeskplusmsp.com