CNNVD-202510-4222 Information
Oct 30, 2025
cve
CNNVD ID
CNNVD-202510-4222
Related CVE
- CNNVD Published: 2025-10-30
Description (Chinese)
ZOHO ManageEngine Exchange Reporter Plus是美国卓豪(ZOHO)公司的一款基于 Web的 Exchange Server 报告软件。 ZOHO ManageEngine Exchange Reporter Plus 5721及之前版本存在安全漏洞,该漏洞源于Instant Search选项存在存储型跨站脚本。
Description (English)
ZOHO ManageEngine Exchange Reporter Plus is a Web-based Exchange Server reporting software for ZOHO. ZOHO ManageEngine Exchange Reporter Plus 5721 and previous versions have a security loophole, which is the result of the storage cross-site script of the Instant Search option.
Hazard Level
High
Vulnerability Type
其他
Affected Vendor
卓豪
Published
2025-10-30
Last Modified
2026-02-24
References
https://www.manageengine.com/products/exchange-reports/advisory/CVE-2025-5343.html
Patch
https://www.manageengine.com/products/exchange-reports/advisory/CVE-2025-5343.html
Share on: