CVE-2026-3880

7.3

Zohocorp · ManageEngine Exchange Reporter Plus

Zohocorp ManageEngine Exchange Reporter Plus is vulnerable to stored cross-site scripting (XSS) within the Public Folder Client Permissions report.

Executive summary

A stored cross-site scripting vulnerability in ManageEngine Exchange Reporter Plus allows authenticated attackers to execute arbitrary scripts in the context of a victim's browser session.

Vulnerability

The application is susceptible to stored cross-site scripting (CWE-79) via the Public Folder Client Permissions report. Successful exploitation requires a low-privileged authenticated user to inject malicious scripts that execute when an administrator or another user views the report.

Business impact

This vulnerability carries a CVSS score of 7.3, indicating a high severity level. Successful exploitation could lead to unauthorized actions performed on behalf of the victim, potentially resulting in session hijacking, data theft, or the modification of sensitive reporting configurations.

Remediation

Immediate Action: Upgrade to ManageEngine Exchange Reporter Plus version 5802 or later as specified in the official vendor advisory.

Proactive Monitoring: Review application access logs for unusual patterns or characters in report parameters and monitor for unauthorized script execution alerts from endpoint protection software.

Compensating Controls: Implement a Web Application Firewall (WAF) to filter malicious input patterns associated with XSS attacks and enforce strict Content Security Policy (CSP) headers.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Given the potential for session compromise and the high CVSS severity rating, administrators should prioritize updating to version 5802 immediately. Ensuring that all users have the latest security patches is the most effective way to eliminate this risk and protect the integrity of the Exchange reporting environment.

More Zohocorp CVEs

Sources

Originally found and disclosed by C311, per the CVE Program record.