Stored XSS Vulnerability in Zohocorp's Exchange Reporter Plus
CVE-2025-7430

7.3HIGH

Key Information:

Vendor

Zohocorp

Vendor
CVE Published:
11 November 2025

What is CVE-2025-7430?

Zohocorp's ManageEngine Exchange Reporter Plus versions 5723 and earlier are susceptible to a Stored Cross-Site Scripting (XSS) vulnerability. This issue arises within the Folder Message Count and Size report feature, allowing unauthorized users to inject malicious scripts. Exploitation of this vulnerability could lead to unauthorized actions on behalf of users and compromise sensitive information.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

ManageEngine Exchange Reporter Plus Windows 0 < 5724

References

CVSS V3.1

Score:
7.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.