Vingroup

6 exploits Active since May 2019
CVE-2019-12189 EXPLOITDB MEDIUM text WRITEUP
Zoho ManageEngine ServiceDesk Plus 9.3 - XSS
An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3. There is XSS via the SearchN.do search field.
CVSS 6.1
CVE-2019-12252 EXPLOITDB MEDIUM text WRITEUP
Zoho ManageEngine ServiceDesk Plus <10.5 - Info Disclosure
In Zoho ManageEngine ServiceDesk Plus through 10.5, users with the lowest privileges (guest) can view an arbitrary post by appending its number to the SDNotify.do?notifyModule=Solution&mode=E-Mail&notifyTo=SOLFORWARD&id= substring.
CVSS 6.5
CVE-2019-12543 EXPLOITDB MEDIUM text WORKING POC
Zohocorp Manageengine Servicedesk Plus - XSS
An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3. There is XSS via the PurchaseRequest.do serviceRequestId parameter.
CVSS 6.1
CVE-2019-12542 EXPLOITDB MEDIUM text WORKING POC
Zohocorp Manageengine Servicedesk Plus - XSS
An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3. There is XSS via the SearchN.do userConfigID parameter.
CVSS 6.1
CVE-2019-12538 EXPLOITDB MEDIUM text WORKING POC
Zohocorp Manageengine Servicedesk Plus - XSS
An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3. There is XSS via the SiteLookup.do search field.
CVSS 6.1
CVE-2019-12541 EXPLOITDB MEDIUM text WORKING POC
Zohocorp Manageengine Servicedesk Plus - XSS
An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3. There is XSS via the SolutionSearch.do searchText parameter.
CVSS 6.1