Vulnerability Database

383,463

Total vulnerabilities in the database

CVE-2024-10839 — zohocorp / manageengine_sharepoint_manager_plus

Improper Restriction of XML External Entity Reference

Zohocorp ManageEngine SharePoint Manager Plus versions 4503 and prior are vulnerable to authenticated XML External Entity (XXE) in the Management option.

  • Published: Nov 8, 2024
  • Updated: Sep 14, 2026
  • CVE: CVE-2024-10839
  • Severity: High
  • Exploit:
  • CISA KEV:

CVSS v3:

  • Severity: High
  • Score: 8.5
  • AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L
Software Affected versions
zohocorp / manageengine_sharepoint_manager_plus = 4.0-4000
zohocorp / manageengine_sharepoint_manager_plus = 4.0-4001
zohocorp / manageengine_sharepoint_manager_plus = 4.0-4002
zohocorp / manageengine_sharepoint_manager_plus = 4.0-4003
zohocorp / manageengine_sharepoint_manager_plus = 4.0-4004
zohocorp / manageengine_sharepoint_manager_plus = 4.0-4005
zohocorp / manageengine_sharepoint_manager_plus = 4.0-4006
zohocorp / manageengine_sharepoint_manager_plus = 4.0-4007
zohocorp / manageengine_sharepoint_manager_plus = 4.0-4008
zohocorp / manageengine_sharepoint_manager_plus = 4.0-4009
zohocorp / manageengine_sharepoint_manager_plus = 4.0-4010
zohocorp / manageengine_sharepoint_manager_plus = 4.0-4011
zohocorp / manageengine_sharepoint_manager_plus = 4.0-4012
zohocorp / manageengine_sharepoint_manager_plus = 4.0-4013
zohocorp / manageengine_sharepoint_manager_plus = 4.0-4014
zohocorp / manageengine_sharepoint_manager_plus = 4.0-4015
zohocorp / manageengine_sharepoint_manager_plus = 4.0-4016
zohocorp / manageengine_sharepoint_manager_plus = 4.0-4017
zohocorp / manageengine_sharepoint_manager_plus = 4.0-4018
zohocorp / manageengine_sharepoint_manager_plus = 4.0-4019
zohocorp / manageengine_sharepoint_manager_plus = 4.0-4020
zohocorp / manageengine_sharepoint_manager_plus = 4.0-4021
zohocorp / manageengine_sharepoint_manager_plus = 4.0-4022
zohocorp / manageengine_sharepoint_manager_plus = 4.0-4023
zohocorp / manageengine_sharepoint_manager_plus = 4.0-4024
zohocorp / manageengine_sharepoint_manager_plus = 4.0-4025
zohocorp / manageengine_sharepoint_manager_plus = 4.0-4026
zohocorp / manageengine_sharepoint_manager_plus = 4.0-4027
zohocorp / manageengine_sharepoint_manager_plus = 4.0-4028
zohocorp / manageengine_sharepoint_manager_plus = 4.0-4029
zohocorp / manageengine_sharepoint_manager_plus = 4.0-4030
zohocorp / manageengine_sharepoint_manager_plus = 4.0-4031
zohocorp / manageengine_sharepoint_manager_plus = 4.0-4032
zohocorp / manageengine_sharepoint_manager_plus = 4.0-4033
zohocorp / manageengine_sharepoint_manager_plus = 4.1-4100
zohocorp / manageengine_sharepoint_manager_plus = 4.1-4101
zohocorp / manageengine_sharepoint_manager_plus = 4.1-4102
zohocorp / manageengine_sharepoint_manager_plus = 4.1-4103
zohocorp / manageengine_sharepoint_manager_plus = 4.1-4104
zohocorp / manageengine_sharepoint_manager_plus = 4.1-4105
zohocorp / manageengine_sharepoint_manager_plus = 4.1-4106
zohocorp / manageengine_sharepoint_manager_plus = 4.1-4107
zohocorp / manageengine_sharepoint_manager_plus = 4.1-4108
zohocorp / manageengine_sharepoint_manager_plus = 4.1-4109
zohocorp / manageengine_sharepoint_manager_plus = 4.1-4110
zohocorp / manageengine_sharepoint_manager_plus = 4.2-4200
zohocorp / manageengine_sharepoint_manager_plus = 4.2-4201
zohocorp / manageengine_sharepoint_manager_plus = 4.3-4300
zohocorp / manageengine_sharepoint_manager_plus = 4.3-4301
zohocorp / manageengine_sharepoint_manager_plus = 4.3-4302
zohocorp / manageengine_sharepoint_manager_plus = 4.3-4303
zohocorp / manageengine_sharepoint_manager_plus = 4.3-4304
zohocorp / manageengine_sharepoint_manager_plus = 4.3-4305
zohocorp / manageengine_sharepoint_manager_plus = 4.3-4306
zohocorp / manageengine_sharepoint_manager_plus = 4.3-4307
zohocorp / manageengine_sharepoint_manager_plus = 4.3-4308
zohocorp / manageengine_sharepoint_manager_plus = 4.3-4309
zohocorp / manageengine_sharepoint_manager_plus = 4.3-4310
zohocorp / manageengine_sharepoint_manager_plus = 4.3-4311
zohocorp / manageengine_sharepoint_manager_plus = 4.3-4312
zohocorp / manageengine_sharepoint_manager_plus = 4.3-4313
zohocorp / manageengine_sharepoint_manager_plus = 4.3-4314
zohocorp / manageengine_sharepoint_manager_plus = 4.3-4315
zohocorp / manageengine_sharepoint_manager_plus = 4.3-4316
zohocorp / manageengine_sharepoint_manager_plus = 4.3-4317
zohocorp / manageengine_sharepoint_manager_plus = 4.3-4318
zohocorp / manageengine_sharepoint_manager_plus = 4.3-4319
zohocorp / manageengine_sharepoint_manager_plus = 4.3-4320
zohocorp / manageengine_sharepoint_manager_plus = 4.3-4321
zohocorp / manageengine_sharepoint_manager_plus = 4.3-4322
zohocorp / manageengine_sharepoint_manager_plus = 4.3-4323
zohocorp / manageengine_sharepoint_manager_plus = 4.3-4324
zohocorp / manageengine_sharepoint_manager_plus = 4.3-4325
zohocorp / manageengine_sharepoint_manager_plus = 4.3-4326
zohocorp / manageengine_sharepoint_manager_plus = 4.3-4327
zohocorp / manageengine_sharepoint_manager_plus = 4.3-4328
zohocorp / manageengine_sharepoint_manager_plus = 4.3-4329
zohocorp / manageengine_sharepoint_manager_plus = 4.3-4330
zohocorp / manageengine_sharepoint_manager_plus = 4.3-4331
zohocorp / manageengine_sharepoint_manager_plus = 4.3-4332
zohocorp / manageengine_sharepoint_manager_plus = 4.3-4333
zohocorp / manageengine_sharepoint_manager_plus = 4.4-4400
zohocorp / manageengine_sharepoint_manager_plus = 4.4-4401
zohocorp / manageengine_sharepoint_manager_plus = 4.4-4402
zohocorp / manageengine_sharepoint_manager_plus = 4.4-4403
zohocorp / manageengine_sharepoint_manager_plus = 4.4-4404
zohocorp / manageengine_sharepoint_manager_plus = 4.5-4500
zohocorp / manageengine_sharepoint_manager_plus = 4.5-4501
zohocorp / manageengine_sharepoint_manager_plus = 4.5-4502
zohocorp / manageengine_sharepoint_manager_plus = 4.5-4503

Frequently Asked Questions

A security vulnerability is a weakness in software, hardware, or configuration that can be exploited to compromise confidentiality, integrity, or availability. Many vulnerabilities are tracked as CVEs (Common Vulnerabilities and Exposures), which provide a standardized identifier so teams can coordinate patching, mitigation, and risk assessment across tools and vendors.

CVSS (Common Vulnerability Scoring System) estimates technical severity, but it doesn't automatically equal business risk. Prioritize using context like internet exposure, affected asset criticality, known exploitation (proof-of-concept or in-the-wild), and whether compensating controls exist. A "Medium" CVSS on an exposed, production system can be more urgent than a "Critical" on an isolated, non-production host.

A vulnerability is the underlying weakness. An exploit is the method or code used to take advantage of it. A zero-day is a vulnerability that is unknown to the vendor or has no publicly available fix when attackers begin using it. In practice, risk increases sharply when exploitation becomes reliable or widespread.

Recurring findings usually come from incomplete Asset Discovery, inconsistent patch management, inherited images, and configuration drift. In modern environments, you also need to watch the software supply chain: dependencies, containers, build pipelines, and third-party services can reintroduce the same weakness even after you patch a single host. Unknown or unmanaged assets (often called Shadow IT) are a common reason the same issues resurface.

Use a simple, repeatable triage model: focus first on externally exposed assets, high-value systems (identity, VPN, email, production), vulnerabilities with known exploits, and issues that enable remote code execution or privilege escalation. Then enforce patch SLAs and track progress using consistent metrics so remediation is steady, not reactive.

SynScan combines attack surface monitoring and continuous security auditing to keep your inventory current, flag high-impact vulnerabilities early, and help you turn raw findings into a practical remediation plan.