CVE-2019-12539: XSS
Published Jul 11, 2019
·Updated
An issue was discovered in the Purchase component of Zoho ManageEngine ServiceDesk Plus. There is XSS via the SearchN.do search field, a different vulnerability than CVE-2019-12189.
Affected Software
1 affected component
ZohoCorp ManageEngine ServiceDesk Plus=10.5
Event History
Jul 11, 2019
CVE Published
via MITRE·01:16 PM
Data Sourced
via MITRE·01:16 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-12539?
The severity of CVE-2019-12539 is medium with a severity value of 6.1.
2
What is the vulnerability type of CVE-2019-12539?
CVE-2019-12539 is a Cross-Site Scripting (XSS) vulnerability.
3
How does CVE-2019-12539 affect Zoho ManageEngine ServiceDesk Plus?
CVE-2019-12539 affects Zoho ManageEngine ServiceDesk Plus version 10.5.
4
How can I fix CVE-2019-12539?
To fix CVE-2019-12539, update Zoho ManageEngine ServiceDesk Plus to the latest version.
5
Where can I find more information about CVE-2019-12539?
You can find more information about CVE-2019-12539 in the references provided: [Link 1](https://github.com/tarantula-team/Multiple-Cross-Site-Scripting-vulnerabilities-in-Zoho-ManageEngine), [Link 2](https://www.manageengine.com/products/service-desk/readme.html).