Junglewise Threat Intelligence

CVE-2026-4107: Zohocorp ManageEngine Exchange Reporter Plus Stored XSS in Reports

CVE-2026-4107 · Severity: high · CVSS 7.3 · Published 2026-04-03

Technologies: Zohocorp Manageengine Exchange Reporter Plus, Zoho Corporation Exchange Reporter Plus. Vendors: Zohocorp, Zoho Corporation.

Executive brief

ManageEngine Exchange Reporter Plus is a reporting and monitoring solution for Microsoft Exchange environments. A security vulnerability in the 'Folder Message Count and Size' report allows an authenticated user to inject malicious scripts into the system. If an administrator or another user views the compromised report, the attacker could gain unauthorized access to the application or perform actions on behalf of the victim.

Technical details

A stored cross-site scripting (XSS) vulnerability exists in ManageEngine Exchange Reporter Plus builds 5801 and below. The flaw is located within the 'Folder Message Count and Size' report component due to improper neutralization of input during web page generation (CWE-79). An authenticated attacker, typically a mailbox user within the Exchange organization, can inject malicious scripts that are stored on the server. When a victim (such as an administrator) interacts with the affected report, the script executes in their browser context, potentially leading to session hijacking or unauthorized administrative actions. The issue is resolved in version 5802 through improved input validation.

Affected products

  • Zohocorp ManageEngine Exchange Reporter Plus Builds 5801 and below

Timeline

  • 2026-03-19: patched: Fixed in version 5802
  • 2026-04-03: advisory: Initial advisory published by ManageEngine and NVD

References

Related threats