CVE-2025-5966 Details
Description
Zohocorp ManageEngine Exchange reporter Plus version 5722 and below are vulnerable to Stored XSS in the Attachments by filename keyword report.
A stored cross-site scripting vulnerability has been identified in ManageEngine Exchange Reporter Plus, affecting version 5722 and below. The issue arises in the 'Attachments by Filename Keyword' report, where user-supplied data is not properly sanitized, allowing for the injection of malicious scripts that are executed when the report is viewed.
Users are advised to update Exchange Reporter Plus to version 5723 or later. The latest service pack can be downloaded from the ManageEngine website. For assistance with the update, contact ManageEngine product support.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 26, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.manageengine.com/products/exchange-reports/advisory/CVE-2025-5966.html | ManageEngine | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | ManageEngine |
Affected Products
| Product | Versions |
|---|---|
| zohocorp manageengine exchange reporter plus | < 5.7 5.7 - 5.7 5700 5.7 5701 5.7 5702 5.7 5703 5.7 5704 5.7 5705 5.7 5706 5.7 5707 5.7 5708 5.7 5709 5.7 5710 5.7 5711 5.7 5712 5.7 5713 5.7 5714 5.7 5715 5.7 5717 5.7 5718 5.7 5719 5.7 5720 5.7 5721 5.7 5722 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | ManageEngine |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Sep 29, 2025 | Initial Analysis | [email protected] |
| Jun 26, 2025 | New CVE Received | ManageEngine |