CVE-2019-8394: Zoho ManageEngine ServiceDesk Plus (SDP) File Upload Vulnerability
Zoho ManageEngine ServiceDesk Plus (SDP) before 10.0 build 10012 allows remote attackers to upload arbitrary files via login page customization.
Other sources
Zoho ManageEngine ServiceDesk Plus (SDP) contains an unspecified vulnerability that allows remote users to upload files via login page customization.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
ManageEngine ServiceDesk Plusto a version that resolves this vulnerability.Fixed in 10.0 build 10012
Event History
Frequently Asked Questions
What is the vulnerability ID for Zoho ManageEngine ServiceDesk Plus file upload vulnerability?
The vulnerability ID for Zoho ManageEngine ServiceDesk Plus file upload vulnerability is CVE-2019-8394.
What is the severity of CVE-2019-8394?
The severity of CVE-2019-8394 is medium, with a severity value of 6.5.
How can remote users exploit CVE-2019-8394?
Remote users can exploit CVE-2019-8394 by uploading files via the login page customization.
Which software is affected by CVE-2019-8394?
Zoho ManageEngine ServiceDesk Plus version up to 10.0 is affected by CVE-2019-8394.
Are there any references for CVE-2019-8394?
Yes, you can find more information about CVE-2019-8394 at the following references: [1] http://www.securityfocus.com/bid/107129, [2] https://www.exploit-db.com/exploits/46413/, [3] https://www.manageengine.com/products/service-desk/readme.html