Zoho ManageEngine SharePoint Manager Plus before 4329 allows account takeover because authorization is mishandled.
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check. This allows attackers to bypass intended access restrictions.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Manageengine_sharepoint_manager_plus | Zohocorp | –build_4000 (including) | –build_4000 (including) |
Manageengine_sharepoint_manager_plus | Zohocorp | –build_4001 (including) | –build_4001 (including) |
Manageengine_sharepoint_manager_plus | Zohocorp | –build_4002 (including) | –build_4002 (including) |
Manageengine_sharepoint_manager_plus | Zohocorp | –build_4003 (including) | –build_4003 (including) |
Manageengine_sharepoint_manager_plus | Zohocorp | –build_4004 (including) | –build_4004 (including) |
Manageengine_sharepoint_manager_plus | Zohocorp | –build_4005 (including) | –build_4005 (including) |
Manageengine_sharepoint_manager_plus | Zohocorp | –build_4006 (including) | –build_4006 (including) |
Manageengine_sharepoint_manager_plus | Zohocorp | –build_4007 (including) | –build_4007 (including) |
Manageengine_sharepoint_manager_plus | Zohocorp | –build_4008 (including) | –build_4008 (including) |
Manageengine_sharepoint_manager_plus | Zohocorp | –build_4009 (including) | –build_4009 (including) |
Manageengine_sharepoint_manager_plus | Zohocorp | –build_4010 (including) | –build_4010 (including) |
Manageengine_sharepoint_manager_plus | Zohocorp | –build_4011 (including) | –build_4011 (including) |
Manageengine_sharepoint_manager_plus | Zohocorp | –build_4012 (including) | –build_4012 (including) |
Manageengine_sharepoint_manager_plus | Zohocorp | –build_4013 (including) | –build_4013 (including) |
Manageengine_sharepoint_manager_plus | Zohocorp | –build_4014 (including) | –build_4014 (including) |
Manageengine_sharepoint_manager_plus | Zohocorp | –build_4015 (including) | –build_4015 (including) |
Manageengine_sharepoint_manager_plus | Zohocorp | –build_4016 (including) | –build_4016 (including) |
Manageengine_sharepoint_manager_plus | Zohocorp | –build_4017 (including) | –build_4017 (including) |
Manageengine_sharepoint_manager_plus | Zohocorp | –build_4018 (including) | –build_4018 (including) |
Manageengine_sharepoint_manager_plus | Zohocorp | –build_4020 (including) | –build_4020 (including) |
Manageengine_sharepoint_manager_plus | Zohocorp | –build_4021 (including) | –build_4021 (including) |
Manageengine_sharepoint_manager_plus | Zohocorp | –build_4022 (including) | –build_4022 (including) |
Manageengine_sharepoint_manager_plus | Zohocorp | –build_4023 (including) | –build_4023 (including) |
Manageengine_sharepoint_manager_plus | Zohocorp | –build_4024 (including) | –build_4024 (including) |
Manageengine_sharepoint_manager_plus | Zohocorp | –build_4025 (including) | –build_4025 (including) |
Manageengine_sharepoint_manager_plus | Zohocorp | –build_4026 (including) | –build_4026 (including) |
Manageengine_sharepoint_manager_plus | Zohocorp | –build_4027 (including) | –build_4027 (including) |
Manageengine_sharepoint_manager_plus | Zohocorp | –build_4028 (including) | –build_4028 (including) |
Manageengine_sharepoint_manager_plus | Zohocorp | –build_4029 (including) | –build_4029 (including) |
Manageengine_sharepoint_manager_plus | Zohocorp | –build_4030 (including) | –build_4030 (including) |
Manageengine_sharepoint_manager_plus | Zohocorp | –build_4031 (including) | –build_4031 (including) |
Manageengine_sharepoint_manager_plus | Zohocorp | –build_4032 (including) | –build_4032 (including) |
Manageengine_sharepoint_manager_plus | Zohocorp | –build_4033 (including) | –build_4033 (including) |
Manageengine_sharepoint_manager_plus | Zohocorp | –build_4100 (including) | –build_4100 (including) |
Manageengine_sharepoint_manager_plus | Zohocorp | –build_4101 (including) | –build_4101 (including) |
Manageengine_sharepoint_manager_plus | Zohocorp | –build_4102 (including) | –build_4102 (including) |
Manageengine_sharepoint_manager_plus | Zohocorp | –build_4103 (including) | –build_4103 (including) |
Manageengine_sharepoint_manager_plus | Zohocorp | –build_4104 (including) | –build_4104 (including) |
Manageengine_sharepoint_manager_plus | Zohocorp | –build_4105 (including) | –build_4105 (including) |
Manageengine_sharepoint_manager_plus | Zohocorp | –build_4106 (including) | –build_4106 (including) |
Manageengine_sharepoint_manager_plus | Zohocorp | –build_4107 (including) | –build_4107 (including) |
Manageengine_sharepoint_manager_plus | Zohocorp | –build_4108 (including) | –build_4108 (including) |
Manageengine_sharepoint_manager_plus | Zohocorp | –build_4109 (including) | –build_4109 (including) |
Manageengine_sharepoint_manager_plus | Zohocorp | –build_4110 (including) | –build_4110 (including) |
Manageengine_sharepoint_manager_plus | Zohocorp | –build_4200 (including) | –build_4200 (including) |
Manageengine_sharepoint_manager_plus | Zohocorp | –build_4201 (including) | –build_4201 (including) |
Manageengine_sharepoint_manager_plus | Zohocorp | –build_4300 (including) | –build_4300 (including) |
Manageengine_sharepoint_manager_plus | Zohocorp | –build_4301 (including) | –build_4301 (including) |
Manageengine_sharepoint_manager_plus | Zohocorp | –build_4302 (including) | –build_4302 (including) |
Manageengine_sharepoint_manager_plus | Zohocorp | –build_4303 (including) | –build_4303 (including) |
Manageengine_sharepoint_manager_plus | Zohocorp | –build_4304 (including) | –build_4304 (including) |
Manageengine_sharepoint_manager_plus | Zohocorp | –build_4305 (including) | –build_4305 (including) |
Manageengine_sharepoint_manager_plus | Zohocorp | –build_4306 (including) | –build_4306 (including) |
Manageengine_sharepoint_manager_plus | Zohocorp | –build_4307 (including) | –build_4307 (including) |
Manageengine_sharepoint_manager_plus | Zohocorp | –build_4308 (including) | –build_4308 (including) |
Manageengine_sharepoint_manager_plus | Zohocorp | –build_4309 (including) | –build_4309 (including) |
Manageengine_sharepoint_manager_plus | Zohocorp | –build_4310 (including) | –build_4310 (including) |
Manageengine_sharepoint_manager_plus | Zohocorp | –build_4311 (including) | –build_4311 (including) |
Manageengine_sharepoint_manager_plus | Zohocorp | –build_4312 (including) | –build_4312 (including) |
Manageengine_sharepoint_manager_plus | Zohocorp | –build_4313 (including) | –build_4313 (including) |
Manageengine_sharepoint_manager_plus | Zohocorp | –build_4314 (including) | –build_4314 (including) |
Manageengine_sharepoint_manager_plus | Zohocorp | –build_4315 (including) | –build_4315 (including) |
Manageengine_sharepoint_manager_plus | Zohocorp | –build_4316 (including) | –build_4316 (including) |
Manageengine_sharepoint_manager_plus | Zohocorp | –build_4317 (including) | –build_4317 (including) |
Manageengine_sharepoint_manager_plus | Zohocorp | –build_4318 (including) | –build_4318 (including) |
Manageengine_sharepoint_manager_plus | Zohocorp | –build_4319 (including) | –build_4319 (including) |
Manageengine_sharepoint_manager_plus | Zohocorp | –build_4320 (including) | –build_4320 (including) |
Manageengine_sharepoint_manager_plus | Zohocorp | –build_4321 (including) | –build_4321 (including) |
Manageengine_sharepoint_manager_plus | Zohocorp | –build_4322 (including) | –build_4322 (including) |
Manageengine_sharepoint_manager_plus | Zohocorp | –build_4323 (including) | –build_4323 (including) |
Manageengine_sharepoint_manager_plus | Zohocorp | –build_4324 (including) | –build_4324 (including) |
Manageengine_sharepoint_manager_plus | Zohocorp | –build_4325 (including) | –build_4325 (including) |
Manageengine_sharepoint_manager_plus | Zohocorp | –build_4326 (including) | –build_4326 (including) |
Manageengine_sharepoint_manager_plus | Zohocorp | –build_4327 (including) | –build_4327 (including) |
Manageengine_sharepoint_manager_plus | Zohocorp | –build_4328 (including) | –build_4328 (including) |
Assuming a user with a given identity, authorization is the process of determining whether that user can access a given resource, based on the user’s privileges and any permissions or other access-control specifications that apply to the resource. When access control checks are incorrectly applied, users are able to access data or perform actions that they should not be allowed to perform. This can lead to a wide range of problems, including information exposures, denial of service, and arbitrary code execution.