CVE-2019-12540: XSS
Published Jul 11, 2019
·Updated
An issue was discovered in Zoho ManageEngine ServiceDesk Plus 10.5. There is XSS via the WorkOrder.do search field.
Affected Software
1 affected component
ZohoCorp ManageEngine ServiceDesk Plus=10.5
Event History
Jul 11, 2019
CVE Published
via MITRE·01:15 PM
Data Sourced
via MITRE·01:15 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-12540?
The severity of CVE-2019-12540 is medium (6.1).
2
How does CVE-2019-12540 affect Zoho ManageEngine ServiceDesk Plus?
CVE-2019-12540 affects Zoho ManageEngine ServiceDesk Plus version 10.5.
3
What is the vulnerability type of CVE-2019-12540?
CVE-2019-12540 is an XSS (Cross-Site Scripting) vulnerability.
4
How can I fix CVE-2019-12540 in Zoho ManageEngine ServiceDesk Plus?
To fix CVE-2019-12540 in Zoho ManageEngine ServiceDesk Plus, update to the latest version or apply the necessary patch provided by Zohocorp.
5
Where can I find more information about CVE-2019-12540?
You can find more information about CVE-2019-12540 on the GitHub repository and the official Zoho ManageEngine ServiceDesk Plus readme.