Stored XSS Vulnerability in Zohocorp ManageEngine Exchange Reporter Plus
CVE-2026-3879
7.3HIGH
What is CVE-2026-3879?
Zohocorp's ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to a Stored Cross-Site Scripting (XSS) flaw in the Equipment Mailbox Details report. This vulnerability could allow attackers to inject malicious scripts that execute in the context of a user’s browser, potentially leading to unauthorized access to sensitive information or further exploitation of the affected system.
Affected Version(s)
ManageEngine Exchange Reporter Plus 0 < 5802