CVE-2019-12542 | Zoho ManageEngine ServiceDesk Plus 9.3 SearchN.do userConfigID cross site scripting (EUVD-2019-4137 / EDB-46965)
A vulnerability described as problematic has been identified in Zoho ManageEngine ServiceDesk Plus 9.3. The impacted element is an unknown function of the file SearchN.do. Such manipulation of the argument userConfigID as part of Parameter leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2019-12542. The attack can be launched remotely. Moreover, an exploit is present.