Stored XSS Vulnerability in Zohocorp's Exchange Reporter Plus
CVE-2025-7430

7.3HIGH

Key Information:

Vendor

Zohocorp

Vendor
CVE Published:
11 November 2025

What is CVE-2025-7430?

Zohocorp's ManageEngine Exchange Reporter Plus versions 5723 and earlier are susceptible to a Stored Cross-Site Scripting (XSS) vulnerability. This issue arises within the Folder Message Count and Size report feature, allowing unauthorized users to inject malicious scripts. Exploitation of this vulnerability could lead to unauthorized actions on behalf of users and compromise sensitive information.

Affected Version(s)

ManageEngine Exchange Reporter Plus Windows 0 < 5724

References

CVSS V3.1

Score:
7.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-7430 : Stored XSS Vulnerability in Zohocorp's Exchange Reporter Plus