Home
CRITICAL: 9.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:HDefault status
unaffected
Any version before 5722
affected
Description
Zohocorp ManageEngine Exchange Reporter Plus versions 5721 and prior are vulnerable to Remote code execution in the Content Search module.
Problem types
CWE-434 Unrestricted Upload of File with Dangerous Type
Product status
Any version before 5722
Credits
Ngockhanhc311 from FPT NightWolf
References
www.manageengine.com/...-reports/advisory/CVE-2025-3835.html