CVE-2024-10839

Severity CVSS v4.0:
Pending analysis
Type:
CWE-611 Improper Restriction of XML External Entity Reference ('XXE')
Publication date:
08/11/2024
Last modified:
13/11/2024

Description

Zohocorp ManageEngine SharePoint Manager Plus versions 4503 and prior are vulnerable to authenticated XML External Entity (XXE) in the Management option.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:zohocorp:manageengine_sharepoint_manager_plus:4.0:4000:*:*:*:*:*:*
cpe:2.3:a:zohocorp:manageengine_sharepoint_manager_plus:4.0:4001:*:*:*:*:*:*
cpe:2.3:a:zohocorp:manageengine_sharepoint_manager_plus:4.0:4002:*:*:*:*:*:*
cpe:2.3:a:zohocorp:manageengine_sharepoint_manager_plus:4.0:4003:*:*:*:*:*:*
cpe:2.3:a:zohocorp:manageengine_sharepoint_manager_plus:4.0:4004:*:*:*:*:*:*
cpe:2.3:a:zohocorp:manageengine_sharepoint_manager_plus:4.0:4005:*:*:*:*:*:*
cpe:2.3:a:zohocorp:manageengine_sharepoint_manager_plus:4.0:4006:*:*:*:*:*:*
cpe:2.3:a:zohocorp:manageengine_sharepoint_manager_plus:4.0:4007:*:*:*:*:*:*
cpe:2.3:a:zohocorp:manageengine_sharepoint_manager_plus:4.0:4008:*:*:*:*:*:*
cpe:2.3:a:zohocorp:manageengine_sharepoint_manager_plus:4.0:4009:*:*:*:*:*:*
cpe:2.3:a:zohocorp:manageengine_sharepoint_manager_plus:4.0:4010:*:*:*:*:*:*
cpe:2.3:a:zohocorp:manageengine_sharepoint_manager_plus:4.0:4011:*:*:*:*:*:*
cpe:2.3:a:zohocorp:manageengine_sharepoint_manager_plus:4.0:4012:*:*:*:*:*:*
cpe:2.3:a:zohocorp:manageengine_sharepoint_manager_plus:4.0:4013:*:*:*:*:*:*
cpe:2.3:a:zohocorp:manageengine_sharepoint_manager_plus:4.0:4014:*:*:*:*:*:*