Home Zohocorp CVE-2024-10839
Back to Zohocorp

CVE-2024-10839

ManageEngine - SharePoint Manager Plus

Zohocorp CVSS 8.5 Updated April 6, 2026

Executive Risk Summary

"ManageEngine SharePoint Manager Plus versions 4503 and prior are vulnerable to an authenticated XML External Entity (XXE) vulnerability in the Management option. This vulnerability could allow an attacker to extract sensitive data or execute system commands on the affected system."

Anticipated Attack Path

  1. 1. Initial Access: Authenticated access to ManageEngine SharePoint Manager Plus
  2. 2. Exploitation: XXE vulnerability in the Management option
  3. 3. Post-Exploitation: Potential data extraction or system command execution

Am I Vulnerable?

  • Verify ManageEngine SharePoint Manager Plus version
  • Check for XXE vulnerability in the Management option
  • Review system logs for suspicious activity

Operational Audit Arsenal

Target Type Windows Service
Target Asset SharePointManagerPlus.exe
Standard Path C:\Program Files\ManageEngine\SharePoint Manager Plus\bin

Manual Verification Required

This is a non-Windows asset (Zohocorp). Use the target asset details and official path provided above to verify your current version against the official vendor advisories listed below.

Patch Impact Forecast

Reboot Required Likely

Potential disruption to SharePoint management and reporting services

Internal Work Notes

CVE-2024-10839: ManageEngine SharePoint Manager Plus XXE vulnerability - apply patch to prevent data extraction or system command execution

Technical Intelligence & Operational Utilities • Delivered Weekly

Intelligence Sources

Related Zohocorp Threats

Data compiled from NVD, MSRC, and CISA KEV Catalog. Intelligence synthesized via AI. Scripts provided for diagnostic purposes under MIT License.