Executive brief
ManageEngine Exchange Reporter Plus, a reporting and auditing tool for Microsoft Exchange servers, is vulnerable to a security flaw in its Distribution Lists report. An attacker with basic access could inject malicious scripts that execute when an administrator views the report. This could allow the attacker to hijack administrative sessions, potentially leading to unauthorized access to sensitive email reporting data or system configuration changes.
Technical details
A stored cross-site scripting (XSS) vulnerability exists in the Distribution Lists report module of ManageEngine Exchange Reporter Plus. The root cause is improper input validation of data used to generate reports. An authenticated attacker with low-level privileges can inject malicious JavaScript into the report database; when a victim (typically an administrator) views the affected report, the script executes in their browser context. This can lead to session hijacking or unauthorized actions performed on behalf of the victim. The issue is resolved in build 5802.
Affected products
- Zohocorp ManageEngine Exchange Reporter Plus Builds 5801 and below
Timeline
- 2026-03-19: patched: Fixed in version 5802
- 2026-04-03: disclosed: Initial advisory publication