CVE-2025-7632: Stored XSS
Zohocorp ManageEngine Exchange Reporter Plus versions 5723 and below are vulnerable to the Stored XSS Vulnerability in the Public Folders report.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-7632?
CVE-2025-7632 is classified as a critical severity vulnerability due to its potential for exploitation through stored XSS attacks.
How do I fix CVE-2025-7632?
To fix CVE-2025-7632, users must upgrade to a version of Zohocorp ManageEngine Exchange Reporter Plus that is newer than 5723.
What are the risks associated with CVE-2025-7632?
The risks include unauthorized access to sensitive data and the possibility of an attacker executing arbitrary scripts in the context of an affected user's session.
Which versions of the software are affected by CVE-2025-7632?
CVE-2025-7632 affects Zohocorp ManageEngine Exchange Reporter Plus version 5723 and below.
Is there a workaround for CVE-2025-7632?
As of now, there are no confirmed workarounds for CVE-2025-7632, and the recommended action is to apply the necessary software updates.