CVE-2026-28703
7.3Zohocorp · ManageEngine Exchange Reporter Plus
ManageEngine Exchange Reporter Plus versions before 5802 are susceptible to a stored cross-site scripting vulnerability within the Mails Exchanged Between Users report.
Executive summary
A stored cross-site scripting vulnerability in ManageEngine Exchange Reporter Plus could allow an authenticated attacker to execute malicious scripts in the context of a user session.
Vulnerability
The application fails to properly neutralize user-supplied input within the Mails Exchanged Between Users report, leading to CWE-79 (Stored XSS). This flaw requires an authenticated user with low privileges to trigger the execution of malicious scripts when a victim views the affected report.
Business impact
Successful exploitation allows an attacker to inject arbitrary scripts that execute when an authorized user accesses the report, potentially leading to session hijacking or unauthorized actions performed on behalf of the victim. With a CVSS score of 7.3, this represents a high-severity risk that could compromise the integrity of administrative sessions and internal communication data.
Remediation
Immediate Action: Update Zohocorp ManageEngine Exchange Reporter Plus to version 5802 or later as specified in the vendor advisory.
Proactive Monitoring: Review web access logs for unusual patterns or suspicious script tags being submitted to report-related parameters.
Compensating Controls: Implement a strict Web Application Firewall (WAF) policy to block suspicious script injections and restrict access to the reporting module to authorized personnel only.
Exploitation status
Public Exploit Available: exploit_available (false)
Analyst recommendation
Given the potential for session compromise and the high CVSS score, organizations should prioritize upgrading their ManageEngine Exchange Reporter Plus installations to version 5802. Prompt patching is the most effective method to eliminate this cross-site scripting risk and protect sensitive user sessions from potential script injection attacks.
More Zohocorp CVEs
Sources
Originally found and disclosed by C311, per the CVE Program record.