CVE-2025-5343: Stored XSS
Zohocorp ManageEngine Exchange Reporter Plus versions through 5721 are vulnerable to Stored Cross Site Scripting in the Instant Search option.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-5343?
CVE-2025-5343 has been classified as a high severity vulnerability due to the potential for attacks leveraging stored cross-site scripting.
How do I fix CVE-2025-5343?
To fix CVE-2025-5343, upgrade Zohocorp ManageEngine Exchange Reporter Plus to version 5722 or later.
What types of attacks are possible with CVE-2025-5343?
CVE-2025-5343 allows attackers to execute malicious scripts in the context of a user's browser session through the Instant Search feature.
Which versions of the software are affected by CVE-2025-5343?
CVE-2025-5343 affects all versions of Zohocorp ManageEngine Exchange Reporter Plus up to and including version 5721.
Is CVE-2025-5343 related to any other vulnerabilities?
CVE-2025-5343 is specifically a stored cross-site scripting vulnerability and does not have direct links to other known vulnerabilities.