← לוח פגיעויות

CVE-2019-8394

בינונית 6.5 מנוצלת בשטח (KEV)

ניצול פעיל מאומת — קטלוג CISA KEV

שם
Zoho ManageEngine ServiceDesk Plus (SDP) File Upload Vulnerability
נוסף לקטלוג
יעד טיפול (פדרלי)
פעולה נדרשת
Apply updates per vendor instructions.

תיאור (מקור, אנגלית)

Zoho ManageEngine ServiceDesk Plus (SDP) before 10.0 build 10012 allows remote attackers to upload arbitrary files via login page customization.

מדדים

CVSS 3.1
6.5 (MEDIUM) מקור הציון: NVD CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
EPSS — סבירות ניצול
64% (אחוזון 100) נכון ל-30/7/2026
CWE
CWE-434

מוצרים מושפעים

zohocorp: manageengine servicedesk plus

קישורים