ZeroHour

CVE-2019-8394

KEV PoC large

Authenticated Arbitrary File Upload in Zoho ManageEngine ServiceDesk Plus

CISA: Zoho ManageEngine ServiceDesk Plus (SDP) File Upload Vulnerability

CVSS 3.1
6.5 medium
EPSS
63%p99
Published
()
KEV added
AI analysis

CVE-2019-8394 is an unrestricted file upload flaw (CWE-434) in Zoho ManageEngine ServiceDesk Plus, located in the login page customization feature. A remote attacker with low-privilege authenticated access can abuse this feature to upload arbitrary files of any type, including JSP web shells, to the server. By planting a web shell, the attacker achieves high-integrity tampering of the system (per the CVSS vector) and, in practice, remote code execution on the ServiceDesk Plus host — a technique consistent with the web shell deployment campaigns highlighted in recent NSA/ASD guidance. All ServiceDesk Plus builds before 10.0 Build 10012 are affected. Exploitation is confirmed in the wild: CISA added the vulnerability to the Known Exploited Vulnerabilities catalog on 2021-11-03, a public proof-of-concept is available (Exploit-DB 46413), and EPSS assigns a 63.3% probability of exploitation within 30 days.

What to do: Upgrade ServiceDesk Plus to 10.0 Build 10012 or later per Zoho's vendor instructions. Because exploitation requires low-privilege credentials, review and rotate service/portal accounts and hunt for attacker-uploaded files or web shells in the application's web directories, especially files dropped through login page customization. Follow NSA/ASD web shell detection guidance and scan for suspicious JSP files and outbound connections if compromise is suspected.

Affected
Zoho Corp (ManageEngine) ManageEngine ServiceDesk PlusAll versions before 10.0 Build 10012 (including 9.x and earlier 10.0 builds)
Estimated exposure
largetens of thousands of enterprise installations, with thousands likely internet-exposed on vulnerable pre-10012 builds — ServiceDesk Plus is one of ManageEngine's flagship ITSM products deployed by tens of thousands of organizations, and public internet scans have repeatedly identified thousands of exposed instances, a substantial share of which run older…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Zoho ManageEngine ServiceDesk Plus (SDP) before 10.0 build 10012 allows remote attackers to upload arbitrary files via login page customization.

CISA Known Exploited Vulnerability
Affected
Zoho ManageEngine
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
zohocorp
Products
manageengine servicedesk plus
Weakness
CWE-434
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

In the news