7.5
CVE-2019-8394
- EPSS 87.94%
- Veröffentlicht 17.02.2019 04:29:00
- Zuletzt bearbeitet 14.03.2025 18:24:37
- Quelle cve@mitre.org
- Teams Watchlist Login
- Unerledigt Login
Zoho ManageEngine ServiceDesk Plus (SDP) before 10.0 build 10012 allows remote attackers to upload arbitrary files via login page customization.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Zohocorp ≫ Manageengine Servicedesk Plus Version < 10.0.0
Zohocorp ≫ Manageengine Servicedesk Plus Version10.0.0 Update-
Zohocorp ≫ Manageengine Servicedesk Plus Version10.0.0 Update10000
Zohocorp ≫ Manageengine Servicedesk Plus Version10.0.0 Update10001
Zohocorp ≫ Manageengine Servicedesk Plus Version10.0.0 Update10002
Zohocorp ≫ Manageengine Servicedesk Plus Version10.0.0 Update10003
Zohocorp ≫ Manageengine Servicedesk Plus Version10.0.0 Update10004
Zohocorp ≫ Manageengine Servicedesk Plus Version10.0.0 Update10005
Zohocorp ≫ Manageengine Servicedesk Plus Version10.0.0 Update10006
Zohocorp ≫ Manageengine Servicedesk Plus Version10.0.0 Update10007
Zohocorp ≫ Manageengine Servicedesk Plus Version10.0.0 Update10008
Zohocorp ≫ Manageengine Servicedesk Plus Version10.0.0 Update10009
Zohocorp ≫ Manageengine Servicedesk Plus Version10.0.0 Update10010
Zohocorp ≫ Manageengine Servicedesk Plus Version10.0.0 Update10011
03.11.2021: CISA Known Exploited Vulnerabilities (KEV) Catalog
Zoho ManageEngine ServiceDesk Plus (SDP) File Upload Vulnerability
SchwachstelleZoho ManageEngine ServiceDesk Plus (SDP) contains an unspecified vulnerability that allows remote users to upload files via login page customization.
BeschreibungApply updates per vendor instructions.
Erforderliche MaßnahmenTyp | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 87.94% | 0.994 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 6.5 | 2.8 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
|
nvd@nist.gov | 4 | 8 | 2.9 |
AV:N/AC:L/Au:S/C:N/I:P/A:N
|
134c704f-9b21-4f2e-91b3-4a467353bcc0 | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
|
CWE-434 Unrestricted Upload of File with Dangerous Type
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.