CVE-2026-3879

7.3

Zohocorp · ManageEngine Exchange Reporter Plus

ManageEngine Exchange Reporter Plus is vulnerable to stored cross-site scripting (XSS) via the Equipment Mailbox Details report, allowing authenticated users to execute malicious scripts.

Executive summary

A stored cross-site scripting vulnerability in ManageEngine Exchange Reporter Plus allows authenticated attackers to inject malicious scripts, potentially leading to unauthorized actions or data access.

Vulnerability

The application is susceptible to stored cross-site scripting (CWE-79) within the Equipment Mailbox Details report. An authenticated attacker with low privileges can inject arbitrary JavaScript that executes in the context of another user's session when they view the compromised report.

Business impact

Successful exploitation of this vulnerability could lead to session hijacking or unauthorized administrative actions performed on behalf of a victim. Given the CVSS score of 7.3, this represents a high risk to organizational security, as it facilitates the compromise of user accounts and potentially sensitive administrative data stored within the reporting interface.

Remediation

Immediate Action: Upgrade Zohocorp ManageEngine Exchange Reporter Plus to build 5802 or later as specified in the official vendor advisory.

Proactive Monitoring: Monitor web access logs for unusual patterns, such as suspicious script tags or encoded characters being submitted to the reporting module.

Compensating Controls: Deploy a Web Application Firewall (WAF) with strict XSS filtering rules to detect and block malicious payloads targeting the reporting endpoints until the update is applied.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

This vulnerability presents a significant risk to the integrity of the Exchange Reporter Plus environment. Security administrators should prioritize the deployment of the vendor-provided update to version 5802 immediately to eliminate the underlying injection flaw and protect against potential session-based attacks.

More Zohocorp CVEs

Sources

Originally found and disclosed by C311, per the CVE Program record.