First published: Sun Feb 17 2019(Updated: )
Zoho ManageEngine ServiceDesk Plus (SDP) before 10.0 build 10012 allows remote attackers to upload arbitrary files via login page customization.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Zohocorp Manageengine Servicedesk Plus | <10.0 | |
Zoho ManageEngine | ||
<10.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for Zoho ManageEngine ServiceDesk Plus file upload vulnerability is CVE-2019-8394.
The severity of CVE-2019-8394 is medium, with a severity value of 6.5.
Remote users can exploit CVE-2019-8394 by uploading files via the login page customization.
Zoho ManageEngine ServiceDesk Plus version up to 10.0 is affected by CVE-2019-8394.
Yes, you can find more information about CVE-2019-8394 at the following references: [1] http://www.securityfocus.com/bid/107129, [2] https://www.exploit-db.com/exploits/46413/, [3] https://www.manageengine.com/products/service-desk/readme.html