CNNVD-202511-1206 Information

CNNVD ID

CNNVD-202511-1206

CVE-2025-7632

  • CNNVD Published: 2025-11-11

Description (Chinese)

ZOHO ManageEngine Exchange reporter Plus是美国卓豪(ZOHO)公司的一款基于Web 的Microsoft Exchange 报告、审核和监控软件。 ZOHO ManageEngine Exchange reporter Plus 5723及之前版本存在安全漏洞,该漏洞源于Public Folders report中存在存储型跨站脚本漏洞。

Description (English)

ZOHO ManageEngine Exchange Reporter Plus is a Web-based Microsoft Exchange reporting, auditing and monitoring software for ZOHO. ZOHO ManageEngine Exchange Reporter Plus 5723 and previous versions have a security loophole, which stems from the storage-type cross-site script loophole in Public Folders reports.

Hazard Level

Medium

Vulnerability Type

其他

Affected Vendor

卓豪

Published

2025-11-11

Last Modified

2026-02-24

References

https://www.manageengine.com/products/exchange-reports/advisory/CVE-2025-7632.html

Patch

https://www.manageengine.com/products/exchange-reports/advisory/CVE-2025-7632.html

Share on: