Zohocorp ManageEngine Exchange reporter Plus version 5722 and below are vulnerable to Stored XSS in the Attachments by filename keyword report.
History

Thu, 26 Jun 2025 13:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 26 Jun 2025 12:45:00 +0000

Type Values Removed Values Added
Description Zohocorp ManageEngine Exchange reporter Plus version 5722 and below are vulnerable to Stored XSS in the Attachments by filename keyword report.
Title Stored XSS
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Zohocorp

Published: 2025-06-26T12:22:10.367Z

Updated: 2025-06-26T12:54:07.728Z

Reserved: 2025-06-10T09:25:22.467Z

Link: CVE-2025-5966

cve-icon Vulnrichment

Updated: 2025-06-26T12:54:04.890Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-06-26T13:15:29.123

Modified: 2025-06-26T18:57:43.670

Link: CVE-2025-5966

cve-icon Redhat

No data.