Vulnerability Database

383,463

Total vulnerabilities in the database

CVE-2022-24305 — zohocorp / manageengine_sharepoint_manager_plus

Improper Privilege Management

Zoho ManageEngine SharePoint Manager Plus before 4329 is vulnerable to a sensitive data leak that leads to privilege escalation.

  • Published: Mar 2, 2022
  • Updated: Sep 14, 2026
  • CVE: CVE-2022-24305
  • Severity: Critical
  • Exploit:
  • CISA KEV:

CVSS v3:

  • Severity: Critical
  • Score: 9.8
  • AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVSS v2:

  • Severity: High
  • Score: 7.5
  • AV:N/AC:L/Au:N/C:P/I:P/A:P

CWEs:

Software Affected versions
zohocorp / manageengine_sharepoint_manager_plus = --build_4000
zohocorp / manageengine_sharepoint_manager_plus = --build_4001
zohocorp / manageengine_sharepoint_manager_plus = --build_4002
zohocorp / manageengine_sharepoint_manager_plus = --build_4003
zohocorp / manageengine_sharepoint_manager_plus = --build_4004
zohocorp / manageengine_sharepoint_manager_plus = --build_4005
zohocorp / manageengine_sharepoint_manager_plus = --build_4006
zohocorp / manageengine_sharepoint_manager_plus = --build_4007
zohocorp / manageengine_sharepoint_manager_plus = --build_4008
zohocorp / manageengine_sharepoint_manager_plus = --build_4009
zohocorp / manageengine_sharepoint_manager_plus = --build_4010
zohocorp / manageengine_sharepoint_manager_plus = --build_4011
zohocorp / manageengine_sharepoint_manager_plus = --build_4012
zohocorp / manageengine_sharepoint_manager_plus = --build_4013
zohocorp / manageengine_sharepoint_manager_plus = --build_4014
zohocorp / manageengine_sharepoint_manager_plus = --build_4015
zohocorp / manageengine_sharepoint_manager_plus = --build_4016
zohocorp / manageengine_sharepoint_manager_plus = --build_4017
zohocorp / manageengine_sharepoint_manager_plus = --build_4018
zohocorp / manageengine_sharepoint_manager_plus = --build_4020
zohocorp / manageengine_sharepoint_manager_plus = --build_4021
zohocorp / manageengine_sharepoint_manager_plus = --build_4022
zohocorp / manageengine_sharepoint_manager_plus = --build_4023
zohocorp / manageengine_sharepoint_manager_plus = --build_4024
zohocorp / manageengine_sharepoint_manager_plus = --build_4025
zohocorp / manageengine_sharepoint_manager_plus = --build_4026
zohocorp / manageengine_sharepoint_manager_plus = --build_4027
zohocorp / manageengine_sharepoint_manager_plus = --build_4028
zohocorp / manageengine_sharepoint_manager_plus = --build_4029
zohocorp / manageengine_sharepoint_manager_plus = --build_4030
zohocorp / manageengine_sharepoint_manager_plus = --build_4031
zohocorp / manageengine_sharepoint_manager_plus = --build_4032
zohocorp / manageengine_sharepoint_manager_plus = --build_4033
zohocorp / manageengine_sharepoint_manager_plus = --build_4100
zohocorp / manageengine_sharepoint_manager_plus = --build_4101
zohocorp / manageengine_sharepoint_manager_plus = --build_4102
zohocorp / manageengine_sharepoint_manager_plus = --build_4103
zohocorp / manageengine_sharepoint_manager_plus = --build_4104
zohocorp / manageengine_sharepoint_manager_plus = --build_4105
zohocorp / manageengine_sharepoint_manager_plus = --build_4106
zohocorp / manageengine_sharepoint_manager_plus = --build_4107
zohocorp / manageengine_sharepoint_manager_plus = --build_4108
zohocorp / manageengine_sharepoint_manager_plus = --build_4109
zohocorp / manageengine_sharepoint_manager_plus = --build_4110
zohocorp / manageengine_sharepoint_manager_plus = --build_4200
zohocorp / manageengine_sharepoint_manager_plus = --build_4201
zohocorp / manageengine_sharepoint_manager_plus = --build_4300
zohocorp / manageengine_sharepoint_manager_plus = --build_4301
zohocorp / manageengine_sharepoint_manager_plus = --build_4302
zohocorp / manageengine_sharepoint_manager_plus = --build_4303
zohocorp / manageengine_sharepoint_manager_plus = --build_4304
zohocorp / manageengine_sharepoint_manager_plus = --build_4305
zohocorp / manageengine_sharepoint_manager_plus = --build_4306
zohocorp / manageengine_sharepoint_manager_plus = --build_4307
zohocorp / manageengine_sharepoint_manager_plus = --build_4308
zohocorp / manageengine_sharepoint_manager_plus = --build_4309
zohocorp / manageengine_sharepoint_manager_plus = --build_4310
zohocorp / manageengine_sharepoint_manager_plus = --build_4311
zohocorp / manageengine_sharepoint_manager_plus = --build_4312
zohocorp / manageengine_sharepoint_manager_plus = --build_4313
zohocorp / manageengine_sharepoint_manager_plus = --build_4314
zohocorp / manageengine_sharepoint_manager_plus = --build_4315
zohocorp / manageengine_sharepoint_manager_plus = --build_4316
zohocorp / manageengine_sharepoint_manager_plus = --build_4317
zohocorp / manageengine_sharepoint_manager_plus = --build_4318
zohocorp / manageengine_sharepoint_manager_plus = --build_4319
zohocorp / manageengine_sharepoint_manager_plus = --build_4320
zohocorp / manageengine_sharepoint_manager_plus = --build_4321
zohocorp / manageengine_sharepoint_manager_plus = --build_4322
zohocorp / manageengine_sharepoint_manager_plus = --build_4323
zohocorp / manageengine_sharepoint_manager_plus = --build_4324
zohocorp / manageengine_sharepoint_manager_plus = --build_4325
zohocorp / manageengine_sharepoint_manager_plus = --build_4326
zohocorp / manageengine_sharepoint_manager_plus = --build_4327
zohocorp / manageengine_sharepoint_manager_plus = --build_4328

Frequently Asked Questions

A security vulnerability is a weakness in software, hardware, or configuration that can be exploited to compromise confidentiality, integrity, or availability. Many vulnerabilities are tracked as CVEs (Common Vulnerabilities and Exposures), which provide a standardized identifier so teams can coordinate patching, mitigation, and risk assessment across tools and vendors.

CVSS (Common Vulnerability Scoring System) estimates technical severity, but it doesn't automatically equal business risk. Prioritize using context like internet exposure, affected asset criticality, known exploitation (proof-of-concept or in-the-wild), and whether compensating controls exist. A "Medium" CVSS on an exposed, production system can be more urgent than a "Critical" on an isolated, non-production host.

A vulnerability is the underlying weakness. An exploit is the method or code used to take advantage of it. A zero-day is a vulnerability that is unknown to the vendor or has no publicly available fix when attackers begin using it. In practice, risk increases sharply when exploitation becomes reliable or widespread.

Recurring findings usually come from incomplete Asset Discovery, inconsistent patch management, inherited images, and configuration drift. In modern environments, you also need to watch the software supply chain: dependencies, containers, build pipelines, and third-party services can reintroduce the same weakness even after you patch a single host. Unknown or unmanaged assets (often called Shadow IT) are a common reason the same issues resurface.

Use a simple, repeatable triage model: focus first on externally exposed assets, high-value systems (identity, VPN, email, production), vulnerabilities with known exploits, and issues that enable remote code execution or privilege escalation. Then enforce patch SLAs and track progress using consistent metrics so remediation is steady, not reactive.

SynScan combines attack surface monitoring and continuous security auditing to keep your inventory current, flag high-impact vulnerabilities early, and help you turn raw findings into a practical remediation plan.