Collected research
Chaining Three Bugs to Access All Your ServiceNow Data
ServiceNow renders Jelly templates twice, and any query parameter binds to a template variable, so ?jvar_page_title= injects into a no_escape title. The HTML sanitiser permits <style>, whose contents the XML parser still reads as tags, and the injection guard only matches a glide namespace declaration written with double quotes, so single quotes rebind the prefix and execute script pre-auth. A path check then strips .. from filenames, so co..nf/glide.db.properties evades the /conf/ blacklist.
Record
- Researcher
- Adam Kues
- Published by
- assetnote.io
- Topic
- Other
In the archive
Related sources
Tags
This page is the archive's own catalogue record. The research is the work of Adam Kues, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .