Stored XSS Vulnerability in Zohocorp's Exchange Reporter Plus
CVE-2025-7430
7.3HIGH
What is CVE-2025-7430?
Zohocorp's ManageEngine Exchange Reporter Plus versions 5723 and earlier are susceptible to a Stored Cross-Site Scripting (XSS) vulnerability. This issue arises within the Folder Message Count and Size report feature, allowing unauthorized users to inject malicious scripts. Exploitation of this vulnerability could lead to unauthorized actions on behalf of users and compromise sensitive information.
Affected Version(s)
ManageEngine Exchange Reporter Plus Windows 0 < 5724