Vulnerability record · CVE-2019-8394 · published 17 February 2019
CVE-2019-8394: Zoho ManageEngine ServiceDesk Plus unrestricted file upload via login page customization
Zohocorp · Manageengine Servicedesk Plus
Zoho ManageEngine ServiceDesk Plus before 10.0 build 10012 permits remote attackers to upload arbitrary files through the login page customization feature. Because uploaded files are not properly restricted, an authenticated attacker can place executable content on the server, which is a well-known path to remote code execution. The flaw is listed in CISA's Known Exploited Vulnerabilities catalog, so it is not merely theoretical.
Description
Zoho ManageEngine ServiceDesk Plus (SDP) before 10.0 build 10012 allows remote attackers to upload arbitrary files via login page customization.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Automated analysis
high priorityThe flaw is in CISA's KEV catalog with a public exploit and very high EPSS score, but it requires an authenticated low-privileged account and the CVSS base score is only 6.5.
What it is
Zoho ManageEngine ServiceDesk Plus before 10.0 build 10012 permits remote attackers to upload arbitrary files through the login page customization feature. Because uploaded files are not properly restricted, an authenticated attacker can place executable content on the server, which is a well-known path to remote code execution. The flaw is listed in CISA's Known Exploited Vulnerabilities catalog, so it is not merely theoretical.
Impact
An attacker with a valid low-privileged account can write arbitrary files to the server, potentially achieving code execution or otherwise compromising the host. The CVSS vector rates integrity impact as high, with no confidentiality or availability impact stated.
Attack surface
The vulnerability is reachable over the network through the login page customization function, requiring a low-privileged authenticated session and no user interaction. The CVSS vector is AV:N/AC:L/PR:L/UI:N, so any account able to reach that customization feature is enough.
Exploitation
CVE-2019-8394 is in CISA's KEV catalog with a 2021-11-03 addition date, and a public Exploit-DB entry (46413) exists. EPSS gives a 30-day exploitation probability of roughly 0.63, at the 99th percentile, indicating high observed likelihood.
What to do
- Upgrade ServiceDesk Plus to 10.0 build 10012 or later, per the vendor release notes.
- If immediate upgrade is not possible, restrict access to the login page customization feature to trusted administrators only.
- Enforce least privilege and review which accounts can reach customization or upload functionality.
- Monitor and restrict outbound and inbound access to the ServiceDesk Plus web interface at the network edge.
- Verify file upload handling and storage paths for executable content after patching.
Detection
- Alert on file writes to ServiceDesk Plus web-accessible directories, especially unexpected script or executable extensions.
- Audit login page customization changes and correlate them with the account that made them.
- Hunt for requests to customization or upload endpoints from unusual source IPs or user agents.
- Review web server logs for POST requests to customization paths followed by access to newly written files.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2019-8394 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "Zoho ManageEngine ServiceDesk Plus (SDP) File Upload Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 3 May 2022.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.securityfocus.com/bid/107129 | Third Party AdvisoryVDB Entry |
| https://www.exploit-db.com/exploits/46413/ | ExploitThird Party AdvisoryVDB Entry |
| https://www.manageengine.com/products/service-desk/readme.html | Release NotesVendor Advisory |
| http://www.securityfocus.com/bid/107129 | Third Party AdvisoryVDB Entry |
| https://www.exploit-db.com/exploits/46413/ | ExploitThird Party AdvisoryVDB Entry |
| https://www.manageengine.com/products/service-desk/readme.html | Release NotesVendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-8394 | US Government Resource |
Track CVE-2019-8394 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2019-8394), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.