vulnerability

ManageEngine ServiceDesk Plus - CVE-2019-8394: Authenticated arbitrary file upload

Severity
7
CVSS
(AV:N/AC:L/Au:S/C:N/I:P/A:N)
Published
Feb 16, 2019
Added
Dec 10, 2020
Modified
May 3, 2022

Description


Zoho ManageEngine ServiceDesk Plus (SDP) before 10.0 build 10012 allows remote attackers to upload arbitrary files via login page customization.

Authentication, at least in the form of a low-privileged user account, is required to exploit this vulnerability. Uploaded files may be leveraged to execute code in the context of the web application.

Solution

http-manageengine-servicedesk-plus-upgrade-latest
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.