CVE-2019-8394highunder attackCWE-434

CVE-2019-8394

Published · Updated

98Vexday Risk Score

Patch now. It under exploitation confirmed by CISA and has a working public exploit.

ssvc Actcvss 7.5epss 63%
from disclosure to weapon1 days
Published on NVDFeb 17
1st PoC+1d
metasploitAug 20
CISA KEV+990d
exploitation probability
63%top 1% of all CVEs
observed exploitation
yesCISA + VulnCheck
2 public exploit(s)
Action required by CISAfederal deadline: 2022-05-03

Apply updates per vendor instructions.

In short

Zoho ManageEngine ServiceDesk Plus before version 10.0 build 10012 allows attackers to upload any file they want through a login page customization feature. This can lead to running malicious code on the server.

Technical detail

CWE-434 unrestricted file upload vulnerability in the login page customization functionality allows unauthenticated remote attackers to upload arbitrary files without proper validation. Successful exploitation enables remote code execution with the privileges of the affected service.

Summary generated and translated by AI from the official description.

The full analysis of this CVE is available in Portuguese →

Zoho ManageEngine ServiceDesk Plus (SDP) before 10.0 build 10012 allows remote attackers to upload arbitrary files via login page customization.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.