CVE-2025-5343

MEDIUM

Zohocorp Manageengine Exchange Reporter Plus < 5.7 - XSS

Title source: rule

Description

Zohocorp ManageEngine Exchange Reporter Plus versions through 5721 are vulnerable to Stored Cross Site Scripting in the Instant Search option.

Scores

CVSS v3 6.3
EPSS 0.0006
EPSS Percentile 17.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:H/A:N

Classification

CWE
CWE-79
Status published

Affected Products (23)

zohocorp/manageengine_exchange_reporter_plus < 5.7
zohocorp/manageengine_exchange_reporter_plus
zohocorp/manageengine_exchange_reporter_plus
zohocorp/manageengine_exchange_reporter_plus
zohocorp/manageengine_exchange_reporter_plus
zohocorp/manageengine_exchange_reporter_plus
zohocorp/manageengine_exchange_reporter_plus
zohocorp/manageengine_exchange_reporter_plus
zohocorp/manageengine_exchange_reporter_plus
zohocorp/manageengine_exchange_reporter_plus
zohocorp/manageengine_exchange_reporter_plus
zohocorp/manageengine_exchange_reporter_plus
zohocorp/manageengine_exchange_reporter_plus
zohocorp/manageengine_exchange_reporter_plus
zohocorp/manageengine_exchange_reporter_plus
... and 8 more

Timeline

Published Oct 30, 2025
Tracked Since Feb 18, 2026