PT-2025-44413 · Manageengine · Exchange Reporter Plus

Published

2025-05-29

·

Updated

2025-11-07

·

CVE-2025-5343

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:S/C:P/I:C/A:N
Name of the Vulnerable Software and Affected Versions ManageEngine Exchange Reporter Plus versions through 5721
Description The software is susceptible to a Stored Cross Site Scripting issue within the Instant Search functionality. The issue allows for the injection of malicious scripts that are stored on the target server and executed when other users access the affected feature.
Recommendations Update to a version later than 5721.

Fix

XSS

Weakness Enumeration

Related Identifiers

BDU:2025-16436
CVE-2025-5343

Affected Products

Exchange Reporter Plus