vulnerability

ManageEngine ServiceDesk Plus - CVE-2019-8394: Authenticated arbitrary file upload

Severity
7
CVSS
(AV:N/AC:L/Au:S/C:N/I:P/A:N)
Published
Feb 16, 2019
Added
Dec 10, 2020
Modified
May 3, 2022

Description


Zoho ManageEngine ServiceDesk Plus (SDP) before 10.0 build 10012 allows remote attackers to upload arbitrary files via login page customization.

Authentication, at least in the form of a low-privileged user account, is required to exploit this vulnerability. Uploaded files may be leveraged to execute code in the context of the web application.

Solution

http-manageengine-servicedesk-plus-upgrade-latest
Title
Rapid7 Labs

2026 Global Threat Landscape Report

The predictive window has collapsed. Exploitation follows disclosure in days. See how attackers are accelerating and how to stay ahead.