CVE-2019-12189

MEDIUM

Zoho ManageEngine ServiceDesk Plus 9.3 - XSS

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2019-12189. PoCs published by Vingroup, falconz.

AI-analyzed exploit summary The exploit describes a Cross-Site Scripting (XSS) vulnerability in Zoho ManageEngine ServiceDesk Plus 9.3 via the SearchN.do search field. The payload leverages confusion between single quotes and semicolons in the query string to execute arbitrary JavaScript.

Description

An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3. There is XSS via the SearchN.do search field.

Exploits (2)

exploitdb WRITEUP
by Vingroup · textwebappsmultiple
https://www.exploit-db.com/exploits/46895

The exploit describes a Cross-Site Scripting (XSS) vulnerability in Zoho ManageEngine ServiceDesk Plus 9.3 via the SearchN.do search field. The payload leverages confusion between single quotes and semicolons in the query string to execute arbitrary JavaScript.

Classification
Writeup 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: Zoho ManageEngine ServiceDesk Plus 9.3
No auth needed
Prerequisites: Access to the SearchN.do endpoint
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WRITEUP
by falconz · poc
https://github.com/falconz/CVE-2019-12189

The repository provides a technical description of a reflected XSS vulnerability in Zoho ManageEngine ServiceDesk Plus 9.3, detailing the attack vector and payload. It includes screenshots but lacks functional exploit code.

Classification
Writeup 80%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: Zoho ManageEngine ServiceDesk Plus 9.3
No auth needed
Prerequisites: Access to the target application's URL
MITRE ATT&CK
devstral-2 · analyzed Feb 18, 2026 Full analysis →

References (3)

Core 3
Core References
Release Notes, Vendor Advisory x_refsource_misc
https://www.manageengine.com/products/service-desk/readme.html
Exploit, Third Party Advisory x_refsource_misc
https://github.com/tuyenhva/CVE-2019-12189

Scores

CVSS v3 6.1
EPSS 0.0682
EPSS Percentile 91.6%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (1)
zohocorp/manageengine_servicedesk_plus 9.3
Published May 21, 2019
Tracked Since Feb 18, 2026