CVE-2019-8394

Zoho ManageEngine ServiceDesk Plus (SDP) before 10.0 build 10012 allows remote attackers to upload arbitrary files via login page customization.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.5 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
mitreCNA
---
---
CVEADP
---
---
CISA-ADPADP
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 99%
VendorProductVersion
zohocorpmanageengine_servicedesk_plus
𝑥
< 10.0.0
zohocorpmanageengine_servicedesk_plus
10.0.0
zohocorpmanageengine_servicedesk_plus
10.0.0:10000
zohocorpmanageengine_servicedesk_plus
10.0.0:10001
zohocorpmanageengine_servicedesk_plus
10.0.0:10002
zohocorpmanageengine_servicedesk_plus
10.0.0:10003
zohocorpmanageengine_servicedesk_plus
10.0.0:10004
zohocorpmanageengine_servicedesk_plus
10.0.0:10005
zohocorpmanageengine_servicedesk_plus
10.0.0:10006
zohocorpmanageengine_servicedesk_plus
10.0.0:10007
zohocorpmanageengine_servicedesk_plus
10.0.0:10008
zohocorpmanageengine_servicedesk_plus
10.0.0:10009
zohocorpmanageengine_servicedesk_plus
10.0.0:10010
zohocorpmanageengine_servicedesk_plus
10.0.0:10011
𝑥
= Vulnerable software versions