CNNVD-202511-1217 Information

CNNVD ID

CNNVD-202511-1217

CVE-2025-7429

  • CNNVD Published: 2025-11-11

Description (Chinese)

ZOHO ManageEngine Exchange reporter Plus是美国卓豪(ZOHO)公司的一款基于Web 的Microsoft Exchange 报告、审核和监控软件。 ZOHO ManageEngine Exchange reporter Plus 5723及之前版本存在安全漏洞,该漏洞源于Mails Deleted或Moved报告存在存储型跨站脚本漏洞。

Description (English)

ZOHO ManageEngine Exchange Reporter Plus is a Web-based Microsoft Exchange reporting, auditing and monitoring software for ZOHO. ZOHO ManageEngine Exchange Reporter Plus 5723 and previous versions have a security loophole, which stems from storage-type cross-site scripts in the Mails Deleted or Moved reports.

Hazard Level

Medium

Vulnerability Type

其他

Affected Vendor

卓豪

Published

2025-11-11

Last Modified

2026-02-24

References

https://www.manageengine.com/products/exchange-reports/advisory/CVE-2025-7429.html

Patch

https://www.manageengine.com/products/exchange-reports/advisory/CVE-2025-7429.html

Share on: