CVE-2026-4107
7.3Zohocorp · ManageEngine Exchange Reporter Plus
ManageEngine Exchange Reporter Plus is vulnerable to Stored Cross-Site Scripting (XSS) within the Folder Message Count and Size report, allowing for potential malicious script injection.
Executive summary
A Stored XSS vulnerability in ManageEngine Exchange Reporter Plus, identified as CVE-2026-4107, poses a risk of unauthorized script execution and potential session compromise for authenticated users.
Vulnerability
The application is susceptible to a Stored Cross-Site Scripting (XSS) flaw in the Folder Message Count and Size report. This vulnerability requires a low-privileged authenticated attacker to inject malicious scripts that execute in the context of an unsuspecting user session.
Business impact
The successful exploitation of this vulnerability could allow an attacker to execute arbitrary scripts in the browser of an authenticated user, leading to session hijacking, unauthorized actions, or information disclosure. With a CVSS score of 7.3, the vulnerability is classified as High, reflecting the significant impact on data integrity and user confidentiality within the administrative environment.
Remediation
Immediate Action: Upgrade Zohocorp ManageEngine Exchange Reporter Plus to version 5802 or later as specified in the official vendor advisory.
Proactive Monitoring: Review web application access logs for suspicious input patterns, specifically those containing script tags or encoded characters within reporting parameters.
Compensating Controls: Implement or tune a Web Application Firewall (WAF) to detect and block malicious script payloads targeting common reporting endpoints.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
Given the High severity rating, organizations should prioritize the application of the vendor-provided patch to remediate the vulnerability. Failure to update may expose internal administrative sessions to malicious activity, and patching should be conducted as part of the next standard maintenance cycle or sooner if the environment is highly exposed.
More Zohocorp CVEs
Sources
Originally found and disclosed by C311, per the CVE Program record.