CVE-2025-3835

CRITICAL

Zohocorp Manageengine Exchange Report... - Unrestricted File Upload

Title source: rule

Description

Zohocorp ManageEngine Exchange Reporter Plus versions 5721 and prior are vulnerable to Remote code execution in the Content Search module.

Scores

CVSS v3 9.6
EPSS 0.0127
EPSS Percentile 79.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Classification

CWE
CWE-434
Status published

Affected Products (23)

zohocorp/manageengine_exchange_reporter_plus < 5.7
zohocorp/manageengine_exchange_reporter_plus
zohocorp/manageengine_exchange_reporter_plus
zohocorp/manageengine_exchange_reporter_plus
zohocorp/manageengine_exchange_reporter_plus
zohocorp/manageengine_exchange_reporter_plus
zohocorp/manageengine_exchange_reporter_plus
zohocorp/manageengine_exchange_reporter_plus
zohocorp/manageengine_exchange_reporter_plus
zohocorp/manageengine_exchange_reporter_plus
zohocorp/manageengine_exchange_reporter_plus
zohocorp/manageengine_exchange_reporter_plus
zohocorp/manageengine_exchange_reporter_plus
zohocorp/manageengine_exchange_reporter_plus
zohocorp/manageengine_exchange_reporter_plus
... and 8 more

Timeline

Published Jun 09, 2025
Tracked Since Feb 18, 2026