← KEV catalog
CISA known exploited vulnerability

CVE-2019-8394

Zoho ManageEngine ServiceDesk Plus (SDP) File Upload Vulnerability

SOURCE FACT

Zoho · ManageEngine

Zoho ManageEngine ServiceDesk Plus (SDP) contains an unspecified vulnerability that allows remote users to upload files via login page customization.

Required action

Apply updates per vendor instructions.

CISA notes

https://nvd.nist.gov/vuln/detail/CVE-2019-8394

View source evidence →

CHECK YOUR OUTSIDE-IN INVENTORY

Could this product be present?