4.3
CVSSv2

CVE-2019-12542

Published: 05/06/2019 Updated: 06/06/2019
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

An issue exists in Zoho ManageEngine ServiceDesk Plus 9.3. There is XSS via the SearchN.do userConfigID parameter.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

zohocorp manageengine servicedesk plus 9.3

Exploits

Zoho ManageEngine ServiceDesk Plus version 93 suffers from multiple cross site scripting vulnerabilities ...

Github Repositories

CVE-2019-12542 Zoho ManageEngine ServiceDesk Plus 93 XSS vulnerability in SearchNdo Information Description: An issue was discovered in Zoho ManageEngine ServiceDesk Plus 93 There is XSS via the SearchNdo userConfigID parameter Author: Concobe of Tarantula Team - VinCSS (a member of Vingroup) Payload domain/SearchNdo?searchText=a&SELECTEDSITEID=1&SELECTED