← Vulnerability feed

Vulnerability record · CVE-2019-8394 · published 17 February 2019

CVE-2019-8394: Zoho ManageEngine ServiceDesk Plus unrestricted file upload via login page customization

Zohocorp · Manageengine Servicedesk Plus

Zoho ManageEngine ServiceDesk Plus before 10.0 build 10012 permits remote attackers to upload arbitrary files through the login page customization feature. Because uploaded files are not properly restricted, an authenticated attacker can place executable content on the server, which is a well-known path to remote code execution. The flaw is listed in CISA's Known Exploited Vulnerabilities catalog, so it is not merely theoretical.

6.5 CVSS 3.1 Medium CISA KEV since 3 Nov 2021 EPSS 63% · top 0.8% CWE-434 · Unrestricted file upload
6.5CVSS 3.1 base score, v2 4.0
63%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
7References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

Zoho ManageEngine ServiceDesk Plus (SDP) before 10.0 build 10012 allows remote attackers to upload arbitrary files via login page customization.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

high priorityThe flaw is in CISA's KEV catalog with a public exploit and very high EPSS score, but it requires an authenticated low-privileged account and the CVSS base score is only 6.5.

What it is

Zoho ManageEngine ServiceDesk Plus before 10.0 build 10012 permits remote attackers to upload arbitrary files through the login page customization feature. Because uploaded files are not properly restricted, an authenticated attacker can place executable content on the server, which is a well-known path to remote code execution. The flaw is listed in CISA's Known Exploited Vulnerabilities catalog, so it is not merely theoretical.

Impact

An attacker with a valid low-privileged account can write arbitrary files to the server, potentially achieving code execution or otherwise compromising the host. The CVSS vector rates integrity impact as high, with no confidentiality or availability impact stated.

Attack surface

The vulnerability is reachable over the network through the login page customization function, requiring a low-privileged authenticated session and no user interaction. The CVSS vector is AV:N/AC:L/PR:L/UI:N, so any account able to reach that customization feature is enough.

Exploitation

CVE-2019-8394 is in CISA's KEV catalog with a 2021-11-03 addition date, and a public Exploit-DB entry (46413) exists. EPSS gives a 30-day exploitation probability of roughly 0.63, at the 99th percentile, indicating high observed likelihood.

What to do

  • Upgrade ServiceDesk Plus to 10.0 build 10012 or later, per the vendor release notes.
  • If immediate upgrade is not possible, restrict access to the login page customization feature to trusted administrators only.
  • Enforce least privilege and review which accounts can reach customization or upload functionality.
  • Monitor and restrict outbound and inbound access to the ServiceDesk Plus web interface at the network edge.
  • Verify file upload handling and storage paths for executable content after patching.

Detection

  • Alert on file writes to ServiceDesk Plus web-accessible directories, especially unexpected script or executable extensions.
  • Audit login page customization changes and correlate them with the account that made them.
  • Hunt for requests to customization or upload endpoints from unusual source IPs or user agents.
  • Review web server logs for POST requests to customization paths followed by access to newly written files.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2019-8394 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "Zoho ManageEngine ServiceDesk Plus (SDP) File Upload Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 3 May 2022.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2019-8394 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-47966Zoho ManageEngine on-premise products RCE via SAML SSO and xmlsecMultiple Zoho ManageEngine on-premise products use Apache Santuario xmlsec 1.4.1, whose XSLT features by design leave certain security protections to…KEVEPSS 100%analysed9.8CVE-2021-44077Zoho ManageEngine ServiceDesk Plus unauthenticated RCEZoho ManageEngine ServiceDesk Plus, ServiceDesk Plus MSP and SupportCenter Plus contain a missing-authentication flaw (CWE-306) in a servlet handling…KEVEPSS 93%analysed9.8CVE-2021-37415Zoho ManageEngine ServiceDesk Plus authentication bypass via REST APIZoho ManageEngine ServiceDesk Plus before build 11302 contains an authentication bypass (CWE-306) that lets a small number of REST-API URLs be reache…KEVEPSS 100%analysed9.8CVE-2021-44526Zohocorp manageengine servicedesk plus vulnerabilityZoho ManageEngine ServiceDesk Plus before 12003 allows authentication bypass in certain admin configurations.EPSS 3.2%9.8CVE-2019-8395Zohocorp manageengine servicedesk plus path traversal vulnerabilityAn Insecure Direct Object Reference (IDOR) vulnerability exists in Zoho ManageEngine ServiceDesk Plus (SDP) before 10.0 build 10007 via an attachment…EPSS 7.1%8.8CVE-2020-35682Zohocorp manageengine servicedesk plus incorrect authorization vulnerabilityZoho ManageEngine ServiceDesk Plus before 11134 allows an Authentication Bypass (only during SAML login).EPSS 7.2%8.8CVE-2017-9362Zohocorp manageengine servicedesk plus xml external entity (xxe) vulnerabilityManageEngine ServiceDesk Plus before 9312 contains an XML injection at add Configuration items CMDB API.EPSS 4.1%8.1CVE-2023-35785Zohocorp manageengine ad360 improper authentication vulnerabilityZoho ManageEngine Active Directory 360 versions 4315 and below, ADAudit Plus 7202 and below, ADManager Plus 7200 and below, Asset Explorer 6993 and b…EPSS 2.4%

Source: NIST National Vulnerability Database (record CVE-2019-8394), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.