CWE
863
Advisory Published
Updated

CVE-2022-24306

First published: Wed Mar 02 2022(Updated: )

Zoho ManageEngine SharePoint Manager Plus before 4329 allows account takeover because authorization is mishandled.

Credit: cve@mitre.org

Affected SoftwareAffected VersionHow to fix
ManageEngine SharePoint Manager Plus=build_4000
ManageEngine SharePoint Manager Plus=build_4001
ManageEngine SharePoint Manager Plus=build_4002
ManageEngine SharePoint Manager Plus=build_4003
ManageEngine SharePoint Manager Plus=build_4004
ManageEngine SharePoint Manager Plus=build_4005
ManageEngine SharePoint Manager Plus=build_4006
ManageEngine SharePoint Manager Plus=build_4007
ManageEngine SharePoint Manager Plus=build_4008
ManageEngine SharePoint Manager Plus=build_4009
ManageEngine SharePoint Manager Plus=build_4010
ManageEngine SharePoint Manager Plus=build_4011
ManageEngine SharePoint Manager Plus=build_4012
ManageEngine SharePoint Manager Plus=build_4013
ManageEngine SharePoint Manager Plus=build_4014
ManageEngine SharePoint Manager Plus=build_4015
ManageEngine SharePoint Manager Plus=build_4016
ManageEngine SharePoint Manager Plus=build_4017
ManageEngine SharePoint Manager Plus=build_4018
ManageEngine SharePoint Manager Plus=build_4020
ManageEngine SharePoint Manager Plus=build_4021
ManageEngine SharePoint Manager Plus=build_4022
ManageEngine SharePoint Manager Plus=build_4023
ManageEngine SharePoint Manager Plus=build_4024
ManageEngine SharePoint Manager Plus=build_4025
ManageEngine SharePoint Manager Plus=build_4026
ManageEngine SharePoint Manager Plus=build_4027
ManageEngine SharePoint Manager Plus=build_4028
ManageEngine SharePoint Manager Plus=build_4029
ManageEngine SharePoint Manager Plus=build_4030
ManageEngine SharePoint Manager Plus=build_4031
ManageEngine SharePoint Manager Plus=build_4032
ManageEngine SharePoint Manager Plus=build_4033
ManageEngine SharePoint Manager Plus=build_4100
ManageEngine SharePoint Manager Plus=build_4101
ManageEngine SharePoint Manager Plus=build_4102
ManageEngine SharePoint Manager Plus=build_4103
ManageEngine SharePoint Manager Plus=build_4104
ManageEngine SharePoint Manager Plus=build_4105
ManageEngine SharePoint Manager Plus=build_4106
ManageEngine SharePoint Manager Plus=build_4107
ManageEngine SharePoint Manager Plus=build_4108
ManageEngine SharePoint Manager Plus=build_4109
ManageEngine SharePoint Manager Plus=build_4110
ManageEngine SharePoint Manager Plus=build_4200
ManageEngine SharePoint Manager Plus=build_4201
ManageEngine SharePoint Manager Plus=build_4300
ManageEngine SharePoint Manager Plus=build_4301
ManageEngine SharePoint Manager Plus=build_4302
ManageEngine SharePoint Manager Plus=build_4303
ManageEngine SharePoint Manager Plus=build_4304
ManageEngine SharePoint Manager Plus=build_4305
ManageEngine SharePoint Manager Plus=build_4306
ManageEngine SharePoint Manager Plus=build_4307
ManageEngine SharePoint Manager Plus=build_4308
ManageEngine SharePoint Manager Plus=build_4309
ManageEngine SharePoint Manager Plus=build_4310
ManageEngine SharePoint Manager Plus=build_4311
ManageEngine SharePoint Manager Plus=build_4312
ManageEngine SharePoint Manager Plus=build_4313
ManageEngine SharePoint Manager Plus=build_4314
ManageEngine SharePoint Manager Plus=build_4315
ManageEngine SharePoint Manager Plus=build_4316
ManageEngine SharePoint Manager Plus=build_4317
ManageEngine SharePoint Manager Plus=build_4318
ManageEngine SharePoint Manager Plus=build_4319
ManageEngine SharePoint Manager Plus=build_4320
ManageEngine SharePoint Manager Plus=build_4321
ManageEngine SharePoint Manager Plus=build_4322
ManageEngine SharePoint Manager Plus=build_4323
ManageEngine SharePoint Manager Plus=build_4324
ManageEngine SharePoint Manager Plus=build_4325
ManageEngine SharePoint Manager Plus=build_4326
ManageEngine SharePoint Manager Plus=build_4327
ManageEngine SharePoint Manager Plus=build_4328

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Frequently Asked Questions

  • What is the severity of CVE-2022-24306?

    CVE-2022-24306 has a severity rating of high due to the potential for account takeover.

  • How do I fix CVE-2022-24306?

    To fix CVE-2022-24306, you should upgrade to version 4329 or later of Zoho ManageEngine SharePoint Manager Plus.

  • Which versions are affected by CVE-2022-24306?

    CVE-2022-24306 affects all versions of Zoho ManageEngine SharePoint Manager Plus prior to build 4329.

  • What impact does CVE-2022-24306 have on security?

    CVE-2022-24306 can allow unauthorized users to gain access to accounts, compromising sensitive data.

  • Is there a patch available for CVE-2022-24306?

    Yes, a patch for CVE-2022-24306 is available in the release version 4329 and later.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2025 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203