CVE-2026-28754

7.3

Zohocorp · ManageEngine Exchange Reporter Plus

Zohocorp ManageEngine Exchange Reporter Plus is affected by a stored cross-site scripting (XSS) vulnerability within the Distribution Lists report functionality.

Executive summary

A stored cross-site scripting vulnerability in ManageEngine Exchange Reporter Plus allows authenticated attackers to execute malicious scripts in the context of a victim's session.

Vulnerability

The application fails to properly neutralize user-supplied input within the Distribution Lists report, leading to stored cross-site scripting (CWE-79). The CVSS vector (PR:L, UI:R) indicates that an authenticated user must trigger the execution of the malicious script by viewing the compromised report.

Business impact

The exploitation of this vulnerability could lead to session hijacking, unauthorized actions performed on behalf of an administrator, or the theft of sensitive session tokens. Given the 7.3 CVSS score, this represents a significant risk to the integrity and confidentiality of the Exchange reporting environment. Successful exploitation may result in the compromise of administrative accounts, potentially leading to broader unauthorized access within the reporting infrastructure.

Remediation

Immediate Action: Upgrade Zohocorp ManageEngine Exchange Reporter Plus to version 5802 or later to address the input neutralization flaw.

Proactive Monitoring: Review web server and application access logs for unusual patterns or payloads within the Distribution Lists report module.

Compensating Controls: Deploy a Web Application Firewall (WAF) with updated rulesets to detect and block common cross-site scripting injection strings.

Exploitation status

Public Exploit Available: No (exploit_available: false).

Analyst recommendation

Organizations utilizing ManageEngine Exchange Reporter Plus should prioritize patching to version 5802 immediately to eliminate this injection vector. Given the nature of stored XSS, the risk persists as long as malicious payloads remain in the system database; therefore, applying the vendor-supplied update is the only definitive path to remediation.

More Zohocorp CVEs

Sources

Originally found and disclosed by C311, per the CVE Program record.