Description
Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Permissions Based on Mailboxes report.
Published: 2026-04-03
Score: 7.3 High
EPSS: < 1% Very Low
KEV: No
Impact: Stored Cross‑Site Scripting (XSS) in report generation
Action: Immediate Patch
AI Analysis

Impact

ManageEngine Exchange Reporter Plus contains a stored XSS flaw in the Permissions Based on Mailboxes report for all releases prior to 5802. An attacker able to inject JavaScript into the report can have that script execute in the web browser of any user who views the report, enabling cookie theft, session hijacking, defacement or further malicious activity. This vulnerability is a typical example of CWE‑79, where client‑side code is injected and used without proper sanitization.

Affected Systems

The affected software is Zohocorp’s ManageEngine Exchange Reporter Plus. Versions before 5802 are known to be vulnerable; this includes the 5.8 series up to the 5801 patch level as reflected in the CMEs. Administrative or end‑user accounts that can request the Permissions Based on Mailboxes report are at risk.

Risk and Exploitability

The CVSS base score of 7.3 indicates high risk, but the exploit probability is unknown because EPSS data is not available in the public record. The vulnerability has not yet appeared in the CISA KEV catalog, suggesting no confirmed production exploitation at this time. Attackers would need authenticated access to the report page, which is typically limited to privileged roles; however, once used, the payload runs in the victim’s context and can exfiltrate data or perform actions on the user’s behalf. It is recommended that defenders prioritize remediation.

Generated by OpenCVE AI on April 3, 2026 at 21:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade ManageEngine Exchange Reporter Plus to version 5802 or later for the official fix.
  • If a patch cannot be applied immediately, restrict or disable the Permissions Based on Mailboxes report for all users that do not require it, or limit access to only trusted administrators.

Generated by OpenCVE AI on April 3, 2026 at 21:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 03 Apr 2026 19:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:zohocorp:manageengine_exchange_reporter_plus:5.8:-:*:*:*:*:*:*
cpe:2.3:a:zohocorp:manageengine_exchange_reporter_plus:5.8:5800:*:*:*:*:*:*
cpe:2.3:a:zohocorp:manageengine_exchange_reporter_plus:5.8:5801:*:*:*:*:*:*

Fri, 03 Apr 2026 14:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 03 Apr 2026 12:45:00 +0000

Type Values Removed Values Added
Description Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Permissions Based on Mailboxes report.
Title Stored XSS Vulnerability
First Time appeared Zohocorp
Zohocorp manageengine Exchange Reporter Plus
Weaknesses CWE-79
CPEs cpe:2.3:a:zohocorp:manageengine_exchange_reporter_plus:*:*:*:*:*:*:*:*
Vendors & Products Zohocorp
Zohocorp manageengine Exchange Reporter Plus
References
Metrics cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N'}


Subscriptions

Zohocorp Manageengine Exchange Reporter Plus
cve-icon MITRE

Status: PUBLISHED

Assigner: Zohocorp

Published:

Updated: 2026-04-04T03:55:17.937Z

Reserved: 2026-03-13T11:43:54.665Z

Link: CVE-2026-27655

cve-icon Vulnrichment

Updated: 2026-04-03T13:09:33.555Z

cve-icon NVD

Status : Analyzed

Published: 2026-04-03T13:17:07.903

Modified: 2026-04-03T18:10:23.540

Link: CVE-2026-27655

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-07T07:55:03Z

Weaknesses