Exploitation Summary
EIP tracks 2 public exploits for CVE-2019-12189. PoCs published by Vingroup, falconz.
AI-analyzed exploit summary The exploit describes a Cross-Site Scripting (XSS) vulnerability in Zoho ManageEngine ServiceDesk Plus 9.3 via the SearchN.do search field. The payload leverages confusion between single quotes and semicolons in the query string to execute arbitrary JavaScript.
Description
An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3. There is XSS via the SearchN.do search field.
Exploits (2)
The exploit describes a Cross-Site Scripting (XSS) vulnerability in Zoho ManageEngine ServiceDesk Plus 9.3 via the SearchN.do search field. The payload leverages confusion between single quotes and semicolons in the query string to execute arbitrary JavaScript.
The repository provides a technical description of a reflected XSS vulnerability in Zoho ManageEngine ServiceDesk Plus 9.3, detailing the attack vector and payload. It includes screenshots but lacks functional exploit code.
References (3)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N