Junglewise Threat Intelligence

CVE-2026-28703: Zohocorp ManageEngine Exchange Reporter Plus stored XSS in reports

CVE-2026-28703 · Severity: high · CVSS 7.3 · Published 2026-04-03

Technologies: Zohocorp Manageengine Exchange Reporter Plus. Vendors: Zohocorp.

Executive brief

ManageEngine Exchange Reporter Plus, a tool used for monitoring and reporting on Microsoft Exchange environments, is vulnerable to a security flaw in its reporting module. An attacker with basic access can inject malicious scripts into specific reports, which then run when an administrator views them. This could allow the attacker to hijack administrative sessions, potentially leading to unauthorized access to sensitive email data or system configurations.

Technical details

A stored cross-site scripting (XSS) vulnerability exists in ManageEngine Exchange Reporter Plus builds 5801 and below. The flaw is located within the 'Mails Exchanged Between Users' report in the Reports module due to improper input validation. An authenticated attacker with low-level privileges can inject malicious scripts that are stored on the server. When a victim (such as an administrator) views the affected report, the script executes in their browser context, potentially allowing the attacker to perform actions with the victim's privileges. The issue is resolved in version 5802.

Affected products

  • Zohocorp ManageEngine Exchange Reporter Plus Builds 5801 and below

Timeline

  • 2026-03-19: patched: Fixed in version 5802
  • 2026-04-03: advisory: Initial advisory published

References