CVE-2019-8394
KEV PoC largeAuthenticated Arbitrary File Upload in Zoho ManageEngine ServiceDesk Plus
CISA: Zoho ManageEngine ServiceDesk Plus (SDP) File Upload Vulnerability
CVE-2019-8394 is an unrestricted file upload flaw (CWE-434) in Zoho ManageEngine ServiceDesk Plus, located in the login page customization feature. A remote attacker with low-privilege authenticated access can abuse this feature to upload arbitrary files of any type, including JSP web shells, to the server. By planting a web shell, the attacker achieves high-integrity tampering of the system (per the CVSS vector) and, in practice, remote code execution on the ServiceDesk Plus host — a technique consistent with the web shell deployment campaigns highlighted in recent NSA/ASD guidance. All ServiceDesk Plus builds before 10.0 Build 10012 are affected. Exploitation is confirmed in the wild: CISA added the vulnerability to the Known Exploited Vulnerabilities catalog on 2021-11-03, a public proof-of-concept is available (Exploit-DB 46413), and EPSS assigns a 63.3% probability of exploitation within 30 days.
What to do: Upgrade ServiceDesk Plus to 10.0 Build 10012 or later per Zoho's vendor instructions. Because exploitation requires low-privilege credentials, review and rotate service/portal accounts and hunt for attacker-uploaded files or web shells in the application's web directories, especially files dropped through login page customization. Follow NSA/ASD web shell detection guidance and scan for suspicious JSP files and outbound connections if compromise is suspected.
| Zoho Corp (ManageEngine) ManageEngine ServiceDesk Plus | All versions before 10.0 Build 10012 (including 9.x and earlier 10.0 builds) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Zoho ManageEngine ServiceDesk Plus (SDP) before 10.0 build 10012 allows remote attackers to upload arbitrary files via login page customization.
- Affected
- Zoho ManageEngine
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- zohocorp
- Products
- manageengine servicedesk plus
- Weakness
- CWE-434
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N