CVE-2026-4107 Details
Description
Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Folder Message Count and Size report.
A stored cross-site scripting vulnerability has been identified in ManageEngine Exchange Reporter Plus, affecting versions prior to 5802. The issue resides in the 'Folder Message Count and Size' report within the Reports module. This vulnerability allows authenticated attackers who are mailbox users in the Exchange organization to execute malicious scripts. Exploitation could lead to unauthorized access to Exchange Reporter Plus, depending on the privileges of the user interacting with the compromised report.
Users can update to Exchange Reporter Plus version 5802 or later. Instructions for downloading the latest version are available on the ManageEngine Exchange Reporter Plus website.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 3, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.manageengine.com/products/exchange-reports/advisory/CVE-2026-4107.html | ManageEngine | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | ManageEngine |
Affected Products
| Product | Versions |
|---|---|
| zohocorp manageengine exchange reporter plus | < 5.8 5.8 - 5.8 5800 5.8 5801 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 24, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | ManageEngine |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 3, 2026 | Initial Analysis | [email protected] |
| Apr 3, 2026 | New CVE Received | ManageEngine |