Description
Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Folder Message Count and Size report.
Published: 2026-04-03
Score: 7.3 High
EPSS: < 1% Very Low
KEV: No
Impact: Client‑side script execution via stored XSS
Action: Immediate Patch
AI Analysis

Impact

A stored cross‑site scripting flaw exists in the Folder Message Count and Size report of Zohocorp ManageEngine Exchange Reporter Plus. Malicious script code can be injected into report data and later executed in the browsers of users who view the affected report, allowing an attacker to run arbitrary JavaScript, deface the interface, or steal authentication tokens. The vulnerability originates from improper sanitization of user‑supplied content that is rendered in the report output and is classified under CWE‑79.

Affected Systems

All installations of ManageEngine Exchange Reporter Plus released prior to version 5802 are affected. The flaw targets the report generation component that aggregates folder statistics, and any system running the vulnerable version is at risk if the report can be accessed via a web browser.

Risk and Exploitability

The CVSS base score of 7.3 indicates high severity, while the EPSS score is not disclosed. The vulnerability is not currently listed in the CISA KEV catalog. Exploitation would likely require an attacker to inject a payload into the data underlying the Folder Message Count and Size report, which could be done by creating or editing folder entries that feed into the report. Once injected, the payload is persisted and executed automatically for any user who opens the report, highlighting a high potential for widespread impact if internal users run the report.

Generated by OpenCVE AI on April 3, 2026 at 15:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade ManageEngine Exchange Reporter Plus to version 5802 or later, which removes the stored XSS flaw.
  • Verify that the upgrade has been applied and test the report to ensure the vulnerability is fixed.

Generated by OpenCVE AI on April 3, 2026 at 15:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 03 Apr 2026 19:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:zohocorp:manageengine_exchange_reporter_plus:5.8:-:*:*:*:*:*:*
cpe:2.3:a:zohocorp:manageengine_exchange_reporter_plus:5.8:5800:*:*:*:*:*:*
cpe:2.3:a:zohocorp:manageengine_exchange_reporter_plus:5.8:5801:*:*:*:*:*:*

Fri, 03 Apr 2026 12:45:00 +0000

Type Values Removed Values Added
Description Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Folder Message Count and Size report.
Title Stored XSS Vulnerability
First Time appeared Zohocorp
Zohocorp manageengine Exchange Reporter Plus
Weaknesses CWE-79
CPEs cpe:2.3:a:zohocorp:manageengine_exchange_reporter_plus:*:*:*:*:*:*:*:*
Vendors & Products Zohocorp
Zohocorp manageengine Exchange Reporter Plus
References
Metrics cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Subscriptions

Zohocorp Manageengine Exchange Reporter Plus
cve-icon MITRE

Status: PUBLISHED

Assigner: Zohocorp

Published:

Updated: 2026-04-03T12:05:11.586Z

Reserved: 2026-03-13T09:31:06.306Z

Link: CVE-2026-4107

cve-icon Vulnrichment

Updated: 2026-04-03T12:05:06.477Z

cve-icon NVD

Status : Analyzed

Published: 2026-04-03T12:16:19.067

Modified: 2026-04-03T18:26:35.067

Link: CVE-2026-4107

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-03T21:16:40Z

Weaknesses