Stored XSS Vulnerability in Zohocorp ManageEngine Exchange Reporter Plus
CVE-2025-7429

7.3HIGH

Key Information:

Vendor

Zohocorp

Vendor
CVE Published:
11 November 2025

What is CVE-2025-7429?

The Stored XSS vulnerability in Zohocorp ManageEngine Exchange Reporter Plus allows unauthorized attackers to inject malicious scripts into the Mails Deleted or Moved report section, potentially compromising user data and application integrity. This flaw, present in versions 5723 and earlier, can be exploited by accessing specific report functionalities, leading to unauthorized actions and exposure of sensitive information.

Affected Version(s)

ManageEngine Exchange Reporter Plus Windows 0 < 5724

References

CVSS V3.1

Score:
7.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-7429 : Stored XSS Vulnerability in Zohocorp ManageEngine Exchange Reporter Plus