Home
HIGH: 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:NDefault status
unaffected
Any version
affected
Description
Zohocorp ManageEngine Exchange reporter Plus version 5722 and below are vulnerable to Stored XSS in the Attachments by filename keyword report.
Problem types
CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')
Product status
Any version
Credits
Ngockhanhc311 from FPT NightWolf
References
www.manageengine.com/...-reports/advisory/CVE-2025-5966.html