Executive brief
ManageEngine Exchange Reporter Plus, a tool used for monitoring and reporting on Microsoft Exchange environments, is vulnerable to a security flaw in its reporting module. An attacker with basic access can inject malicious scripts into specific reports, which then execute when an administrator views them. This could allow the attacker to hijack administrative sessions, potentially leading to unauthorized access to sensitive email data or system configurations.
Technical details
A stored cross-site scripting (XSS) vulnerability exists in ManageEngine Exchange Reporter Plus (builds 5801 and below) within the 'Permissions based on Distribution Groups' report. The root cause is improper neutralization of input during web page generation (CWE-79). An authenticated attacker with low-level privileges can inject malicious scripts into the report data; these scripts are subsequently executed in the browser of any user (typically an administrator) who views the affected report. This can lead to session hijacking or unauthorized actions performed in the context of the victim's browser. The issue is resolved in version 5802 through improved input validation.
Affected products
- Zohocorp ManageEngine Exchange Reporter Plus Builds 5801 and below
Timeline
- 2026-03-19: patched: Fixed in version 5802
- 2026-04-03: disclosed: Initial advisory publication