CVE-2019-8394

MEDIUM KEV

Zohocorp Manageengine Servicedesk Plus - Unrestricted File Upload

Title source: rule

Description

Zoho ManageEngine ServiceDesk Plus (SDP) before 10.0 build 10012 allows remote attackers to upload arbitrary files via login page customization.

Exploits (2)

exploitdb WORKING POC
by Dao Duy Hung · textwebappsjsp
https://www.exploit-db.com/exploits/46413
metasploit WORKING POC EXCELLENT
rubypocjava
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/multi/http/manageengine_sd_uploader.rb

Scores

CVSS v3 6.5
EPSS 0.8752
EPSS Percentile 99.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

Details

CISA KEV 2021-11-03
VulnCheck KEV 2020-12-23
InTheWild.io 2021-07-23
ENISA EUVD EUVD-2019-17784
CWE
CWE-434
Status published
Products (2)
zohocorp/manageengine_servicedesk_plus 10.0.0 (13 CPE variants)
zohocorp/manageengine_servicedesk_plus < 10.0.0
Published Feb 17, 2019
KEV Added Nov 03, 2021
Tracked Since Feb 18, 2026