CVE-2019-12538: XSS
Published Jun 5, 2019
·Updated
An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3. There is XSS via the SiteLookup.do search field.
Affected Software
1 affected component
ZohoCorp ManageEngine ServiceDesk Plus=9.3
Event History
Jun 5, 2019
CVE Published
via MITRE·02:40 PM
Data Sourced
via MITRE·02:40 PM
Description
Frequently Asked Questions
1
What is CVE-2019-12538?
CVE-2019-12538 is a vulnerability discovered in Zoho ManageEngine ServiceDesk Plus 9.3 that allows for XSS attacks via the SiteLookup.do search field.
2
How severe is CVE-2019-12538?
CVE-2019-12538 has a severity rating of medium with a CVSS score of 6.1.
3
How does CVE-2019-12538 affect Zoho ManageEngine ServiceDesk Plus?
CVE-2019-12538 affects Zoho ManageEngine ServiceDesk Plus version 9.3.
4
What is the Common Vulnerabilities and Exposures (CVE) identifier for this vulnerability?
The Common Vulnerabilities and Exposures (CVE) identifier for this vulnerability is CVE-2019-12538.
5
Is there a fix available for CVE-2019-12538?
To fix CVE-2019-12538, upgrade Zoho ManageEngine ServiceDesk Plus to a version higher than 9.3.