CVE-2026-28756

7.3

Zohocorp · ManageEngine Exchange Reporter Plus

ManageEngine Exchange Reporter Plus is vulnerable to a Stored Cross-Site Scripting (XSS) attack within the Permissions based on Distribution Groups report.

Executive summary

A Stored XSS vulnerability in Zohocorp ManageEngine Exchange Reporter Plus allows authenticated users to inject malicious scripts into reports, posing a risk of session hijacking or unauthorized actions.

Vulnerability

This is a Stored Cross-Site Scripting (CWE-79) vulnerability that occurs when the application fails to properly sanitize input within the Permissions based on Distribution Groups report. The vulnerability requires an authenticated user with low privileges to trigger the payload when a victim views the affected report.

Business impact

The vulnerability carries a CVSS score of 7.3, reflecting a high potential for impact on confidentiality and integrity. Successful exploitation could allow an attacker to execute arbitrary scripts in the context of an administrator session, potentially leading to unauthorized system changes, data exfiltration, or complete administrative account compromise. Such incidents result in significant reputational damage and potential loss of sensitive organizational messaging metadata.

Remediation

Immediate Action: Update Zohocorp ManageEngine Exchange Reporter Plus to build 5802 or later as specified in the official vendor security advisory.

Proactive Monitoring: Review application access logs for unusual patterns or characters in report parameters and monitor for unauthorized script execution within the browser sessions of administrative users.

Compensating Controls: Implement a strict Content Security Policy (CSP) and use a Web Application Firewall (WAF) to filter malicious payloads from incoming HTTP requests while the update is being prepared for deployment.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the high CVSS score and the nature of Stored XSS in an enterprise reporting tool, this vulnerability represents a significant risk to administrative account security. Administrators should prioritize the installation of build 5802 immediately to neutralize the injection vector. Continued reliance on unpatched versions of this software exposes the internal environment to potential script-based attacks against high-privilege users.

More Zohocorp CVEs

Sources

Originally found and disclosed by C311, per the CVE Program record.