EXPOSURES › CVE-2019-8394
CVE-2019-8394
HIGH ⌖ ON CISA KEV · EXPLOITEDRemote attackers exploited an unspecified file upload vulnerability in Zoho ManageEngine ServiceDesk Plus to upload files via the login page customization feature.
The vulnerability allowed remote users to upload files through the login page customization, potentially leading to arbitrary code execution if malicious files were uploaded and executed. DIB organizations should care because this represents an unpatched, actively exploited flaw in a widely used IT management tool, increasing the risk of supply-chain compromise and data breaches. Organizations must ensure all ManageEngine products are patched and monitored for similar unpatched vulnerabilities.
Shame score — The vulnerability was actively exploited in the wild and linked to ransomware campaigns, indicating a severe, avoidable failure in patch management and security hygiene.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Zoho ManageEngine ServiceDesk Plus (SDP) contains an unspecified vulnerability that allows remote users to upload files via login page customization.
"Zoho ManageEngine ServiceDesk Plus (SDP) contains an unspecified vulnerability that allows remote users to upload files via login page customization."