vendor:
ManageEngine ServiceDesk Plus
by:
Dao Duy Hung
6.5
CVSS
MEDIUM
Arbitrary File Upload
434
CWE
Product Name: ManageEngine ServiceDesk Plus
Affected Version From: 9.4
Affected Version To: 10.0 build 10012
Patch Exists: NO
Related CWE: CVE-2019-8394
CPE: a:zoho:manageengine_service_desk_plus
Platforms Tested:
2019
Zoho ManageEngine ServiceDesk Plus (SDP) before 10.0 build 10012 – arbitrary file upload
In file common/FileAttachment.jsp line 332 only check file upload extension when parameter 'module' equal to 'SSP' or 'DashBoard' or 'HomePage', and if parameter 'module' is set to 'CustomLogin' will skip check file upload extension function and upload arbitrary file to folder '/custom/login' and this file can access directly from url 'host:port/custom/login/filename' . An authenticated user with minimum permission (ex: guest) can upload webshell to server.
Mitigation:
Upgrade to version 10.0 build 10012 or later.