First published: Thu Jul 11 2019(Updated: )
An issue was discovered in the Purchase component of Zoho ManageEngine ServiceDesk Plus. There is XSS via the SearchN.do search field, a different vulnerability than CVE-2019-12189.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Zohocorp Manageengine Servicedesk Plus | =10.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2019-12539 is medium with a severity value of 6.1.
CVE-2019-12539 is a Cross-Site Scripting (XSS) vulnerability.
CVE-2019-12539 affects Zoho ManageEngine ServiceDesk Plus version 10.5.
To fix CVE-2019-12539, update Zoho ManageEngine ServiceDesk Plus to the latest version.
You can find more information about CVE-2019-12539 in the references provided: [Link 1](https://github.com/tarantula-team/Multiple-Cross-Site-Scripting-vulnerabilities-in-Zoho-ManageEngine), [Link 2](https://www.manageengine.com/products/service-desk/readme.html).