CVE-2019-12541: XSS
Published Jun 5, 2019
·Updated
An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3. There is XSS via the SolutionSearch.do searchText parameter.
Affected Software
1 affected component
ZohoCorp ManageEngine ServiceDesk Plus=9.3
Event History
Jun 5, 2019
CVE Published
via MITRE·02:36 PM
Data Sourced
via MITRE·02:36 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2019-12541.
2
What is the severity of CVE-2019-12541?
The severity of CVE-2019-12541 is medium with a CVSS score of 6.1.
3
What is the affected software?
The affected software is Zoho ManageEngine ServiceDesk Plus version 9.3.
4
What is the description of CVE-2019-12541?
CVE-2019-12541 is a vulnerability in Zoho ManageEngine ServiceDesk Plus 9.3 that allows cross-site scripting (XSS) attacks via the SolutionSearch.do searchText parameter.
5
How can I fix CVE-2019-12541?
To fix CVE-2019-12541, update Zoho ManageEngine ServiceDesk Plus to the latest version provided by Zoho.