PT-2025-46320 · Manageengine · Exchange Reporter Plus

Published

2025-07-25

·

Updated

2025-11-24

·

CVE-2025-7633

CVSS v2.0

8.5

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:N
Name of the Vulnerable Software and Affected Versions ManageEngine Exchange Reporter Plus versions 5723 and below
Description ManageEngine Exchange Reporter Plus versions 5723 and below are susceptible to a Stored Cross-Site Scripting (XSS) issue within the Custom report functionality. This allows for the injection of malicious scripts that can be stored and executed when other users access the affected report.
Recommendations Versions prior to 5723 should be updated.

Fix

XSS

Weakness Enumeration

Related Identifiers

BDU:2025-16380
CVE-2025-7633

Affected Products

Exchange Reporter Plus