Enter of VinCSS (Vingroup)

2 exploits Active since May 2019
CVE-2019-12189 EXPLOITDB MEDIUM text WRITEUP
Zoho ManageEngine ServiceDesk Plus 9.3 - XSS
An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3. There is XSS via the SearchN.do search field.
CVSS 6.1
CVE-2019-12252 EXPLOITDB MEDIUM text WRITEUP
Zoho ManageEngine ServiceDesk Plus <10.5 - Info Disclosure
In Zoho ManageEngine ServiceDesk Plus through 10.5, users with the lowest privileges (guest) can view an arbitrary post by appending its number to the SDNotify.do?notifyModule=Solution&mode=E-Mail&notifyTo=SOLFORWARD&id= substring.
CVSS 6.5