Junglewise Threat Intelligence

CVE-2019-8394: Zoho ManageEngine ServiceDesk Plus (SDP) File Upload Vulnerability

CVE-2019-8394 · Severity: critical · CVSS 7.5 · Exploited in the wild · Published 2021-11-03

Technologies: Zoho ManageEngine. Vendors: Zoho.

Executive brief

Zoho ManageEngine ServiceDesk Plus (SDP) allows remote attackers to upload arbitrary files via the login page customization feature. This unrestricted file upload vulnerability can lead to unauthorized modification of the application.

Affected products

  • Zoho ManageEngine ServiceDesk Plus (SDP) before 10.0 build 10012

Timeline

  • 2019-02-16: disclosed: NVD Published Date
  • 2019-02-19: other: Exploit-DB entry added
  • 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2021-11-03: exploited: Reported as exploited in the wild per CISA KEV data

Related threats