Executive brief
ManageEngine Exchange Reporter Plus, a tool used for monitoring and reporting on Microsoft Exchange environments, is vulnerable to a security flaw in its reporting module. An attacker with basic access can inject malicious scripts into the Public Folder Client Permissions report. If an administrator views this report, the attacker could potentially take control of their session, leading to unauthorized data access or administrative actions within the software.
Technical details
A stored cross-site scripting (XSS) vulnerability exists in ManageEngine Exchange Reporter Plus builds 5801 and below. The flaw is located within the 'Public Folder Client Permissions' report component due to improper neutralization of input during web page generation (CWE-79). An authenticated attacker with low-level privileges can inject malicious scripts that are subsequently executed in the browser of any user (typically an administrator) who views the affected report. This could lead to session hijacking or unauthorized actions performed on behalf of the victim. The issue is resolved in version 5802 through improved input validation.
Affected products
- Zohocorp ManageEngine Exchange Reporter Plus Builds 5801 and below
Timeline
- 2026-03-19: patched: Fixed in version 5802
- 2026-04-03: advisory: Initial advisory published by ManageEngine
- 2026-04-03: disclosed: CVE-2026-3880 published to NVD