CVE-2025-5966

HIGH

Zohocorp Manageengine Exchange Reporter Plus < 5.7 - XSS

Title source: rule

Description

Zohocorp ManageEngine Exchange reporter Plus version 5722 and below are vulnerable to Stored XSS in the Attachments by filename keyword report.

Scores

CVSS v3 8.1
EPSS 0.0110
EPSS Percentile 77.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N

Classification

CWE
CWE-79
Status published

Affected Products (24)

zohocorp/manageengine_exchange_reporter_plus < 5.7
zohocorp/manageengine_exchange_reporter_plus
zohocorp/manageengine_exchange_reporter_plus
zohocorp/manageengine_exchange_reporter_plus
zohocorp/manageengine_exchange_reporter_plus
zohocorp/manageengine_exchange_reporter_plus
zohocorp/manageengine_exchange_reporter_plus
zohocorp/manageengine_exchange_reporter_plus
zohocorp/manageengine_exchange_reporter_plus
zohocorp/manageengine_exchange_reporter_plus
zohocorp/manageengine_exchange_reporter_plus
zohocorp/manageengine_exchange_reporter_plus
zohocorp/manageengine_exchange_reporter_plus
zohocorp/manageengine_exchange_reporter_plus
zohocorp/manageengine_exchange_reporter_plus
... and 9 more

Timeline

Published Jun 26, 2025
Tracked Since Feb 18, 2026