vendor:
ManageEngine ServiceDesk Plus
by:
Tarantula Team - VinCSS
6.1
CVSS
MEDIUM
Cross-Site Scripting
79
CWE
Product Name: ManageEngine ServiceDesk Plus
Affected Version From: Zoho ManageEngine ServiceDesk Plus 9.3
Affected Version To: Zoho ManageEngine ServiceDesk Plus 9.3
Patch Exists: YES
Related CWE: CVE-2019-12541
CPE: a:zohocorp:manageengine_servicedesk_plus:9.3
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: None
2019
Zoho ManageEngine ServiceDesk Plus 9.3 Cross-Site Scripting via SolutionSearch.do
An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3. There is XSS via the SolutionSearch.do searchText parameter.
Mitigation:
Input validation and output encoding should be used to prevent XSS attacks.