← Back

CVE-2024-10839

nvd nist
Published: Nov 8, 2024Modified: Nov 13, 2024

JSON object

Loading...
8.1
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
Exploitability: 2.8 / Impact: 5.2
Source: NVD

Description

Zohocorp ManageEngine SharePoint Manager Plus versions 4503 and prior are vulnerable to authenticated XML External Entity (XXE) in the Management option.

Affected (90)

1 product
Configuration A
90 vulnerable
Vulnerable SoftwareAffected Versions
Zohocorp
Version 4.0 4000
Version 4.0 4001
Version 4.0 4002
Version 4.0 4003
Version 4.0 4004
Version 4.0 4005
Version 4.0 4006
Version 4.0 4007
Version 4.0 4008
Version 4.0 4009
Version 4.0 4010
Version 4.0 4011
Version 4.0 4012
Version 4.0 4013
Version 4.0 4014
Version 4.0 4015
Version 4.0 4016
Version 4.0 4017
Version 4.0 4018
Version 4.0 4019
Version 4.0 4020
Version 4.0 4021
Version 4.0 4022
Version 4.0 4023
Version 4.0 4024
Version 4.0 4025
Version 4.0 4026
Version 4.0 4027
Version 4.0 4028
Version 4.0 4029
Version 4.0 4030
Version 4.0 4031
Version 4.0 4032
Version 4.0 4033
Version 4.1 4100
Version 4.1 4101
Version 4.1 4102
Version 4.1 4103
Version 4.1 4104
Version 4.1 4105
Version 4.1 4106
Version 4.1 4107
Version 4.1 4108
Version 4.1 4109
Version 4.1 4110
Version 4.2 4200
Version 4.2 4201
Version 4.3 4300
Version 4.3 4301
Version 4.3 4302
Version 4.3 4303
Version 4.3 4304
Version 4.3 4305
Version 4.3 4306
Version 4.3 4307
Version 4.3 4308
Version 4.3 4309
Version 4.3 4310
Version 4.3 4311
Version 4.3 4312
Version 4.3 4313
Version 4.3 4314
Version 4.3 4315
Version 4.3 4316
Version 4.3 4317
Version 4.3 4318
Version 4.3 4319
Version 4.3 4320
Version 4.3 4321
Version 4.3 4322
Version 4.3 4323
Version 4.3 4324
Version 4.3 4325
Version 4.3 4326
Version 4.3 4327
Version 4.3 4328
Version 4.3 4329
Version 4.3 4330
Version 4.3 4331
Version 4.3 4332
Version 4.3 4333
Version 4.4 4400
Version 4.4 4401
Version 4.4 4402
Version 4.4 4403
Version 4.4 4404
Version 4.5 4500
Version 4.5 4501
Version 4.5 4502
Version 4.5 4503

References (1)

Timeline

No history available yet.