CVE-2026-28756

HIGH

ManageEngine Exchange Reporter Plus < 5802 - Stored Cross-Site Scripting in Permissions Report

Title source: llm
STIX 2.1

Description

Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Permissions based on Distribution Groups report.

Scores

CVSS v3 7.3
EPSS 0.0002
EPSS Percentile 5.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-79
Status published
Products (3)
Zohocorp/ManageEngine Exchange Reporter Plus < 5802
zohocorp/manageengine_exchange_reporter_plus 5.8 (3 CPE variants)
zohocorp/manageengine_exchange_reporter_plus < 5.8
Published Apr 03, 2026
Tracked Since Apr 03, 2026