7.5
CVE-2019-8394
- EPSS 87.94%
- Published 17.02.2019 04:29:00
- Last modified 14.03.2025 18:24:37
- Source cve@mitre.org
- Teams watchlist Login
- Open Login
Zoho ManageEngine ServiceDesk Plus (SDP) before 10.0 build 10012 allows remote attackers to upload arbitrary files via login page customization.
Data is provided by the National Vulnerability Database (NVD)
Zohocorp ≫ Manageengine Servicedesk Plus Version < 10.0.0
Zohocorp ≫ Manageengine Servicedesk Plus Version10.0.0 Update-
Zohocorp ≫ Manageengine Servicedesk Plus Version10.0.0 Update10000
Zohocorp ≫ Manageengine Servicedesk Plus Version10.0.0 Update10001
Zohocorp ≫ Manageengine Servicedesk Plus Version10.0.0 Update10002
Zohocorp ≫ Manageengine Servicedesk Plus Version10.0.0 Update10003
Zohocorp ≫ Manageengine Servicedesk Plus Version10.0.0 Update10004
Zohocorp ≫ Manageengine Servicedesk Plus Version10.0.0 Update10005
Zohocorp ≫ Manageengine Servicedesk Plus Version10.0.0 Update10006
Zohocorp ≫ Manageengine Servicedesk Plus Version10.0.0 Update10007
Zohocorp ≫ Manageengine Servicedesk Plus Version10.0.0 Update10008
Zohocorp ≫ Manageengine Servicedesk Plus Version10.0.0 Update10009
Zohocorp ≫ Manageengine Servicedesk Plus Version10.0.0 Update10010
Zohocorp ≫ Manageengine Servicedesk Plus Version10.0.0 Update10011
03.11.2021: CISA Known Exploited Vulnerabilities (KEV) Catalog
Zoho ManageEngine ServiceDesk Plus (SDP) File Upload Vulnerability
VulnerabilityZoho ManageEngine ServiceDesk Plus (SDP) contains an unspecified vulnerability that allows remote users to upload files via login page customization.
DescriptionApply updates per vendor instructions.
Required actionsType | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 87.94% | 0.994 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 6.5 | 2.8 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
|
nvd@nist.gov | 4 | 8 | 2.9 |
AV:N/AC:L/Au:S/C:N/I:P/A:N
|
134c704f-9b21-4f2e-91b3-4a467353bcc0 | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
|
CWE-434 Unrestricted Upload of File with Dangerous Type
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.