CVE-2019-8394: Zoho ManageEngine ServiceDesk Plus (SDP) File Upload Vulnerability
Medium severity, CVSS 6.5. Actively exploited: in CISA KEV since 2021-11-03. EPSS: 63.3% chance of exploitation in the next 30 days.
Zoho ManageEngine ServiceDesk Plus (SDP) before 10.0 build 10012 allows remote attackers to upload arbitrary files via login page customization.
Affected products
- Zohocorp ManageEngine ServiceDesk Plus: before 10.0.0 (fixed in 10.0.0); version 10.0.0 only
Published 2019-02-17. Last modified 2026-06-17.