CNNVD-202510-4222 Information

CNNVD ID

CNNVD-202510-4222

CVE-2025-5343

  • CNNVD Published: 2025-10-30

Description (Chinese)

ZOHO ManageEngine Exchange Reporter Plus是美国卓豪(ZOHO)公司的一款基于 Web的 Exchange Server 报告软件。 ZOHO ManageEngine Exchange Reporter Plus 5721及之前版本存在安全漏洞,该漏洞源于Instant Search选项存在存储型跨站脚本。

Description (English)

ZOHO ManageEngine Exchange Reporter Plus is a Web-based Exchange Server reporting software for ZOHO. ZOHO ManageEngine Exchange Reporter Plus 5721 and previous versions have a security loophole, which is the result of the storage cross-site script of the Instant Search option.

Hazard Level

High

Vulnerability Type

其他

Affected Vendor

卓豪

Published

2025-10-30

Last Modified

2026-02-24

References

https://www.manageengine.com/products/exchange-reports/advisory/CVE-2025-5343.html

Patch

https://www.manageengine.com/products/exchange-reports/advisory/CVE-2025-5343.html

Share on: