ManageEngine Exchange Reporter Plus < Build 5802 Multiple Stored XSS

medium Nessus Plugin ID 305773

Synopsis

The remote host is affected by multiple stored cross-site scripting vulnerabilities.

Description

The version of ManageEngine Exchange Reporter Plus on the remote host has a build number prior to 5802. It is, therefore, affected by multiple vulnerabilities, including:

- Stored XSS in the Folder Message Count and Size report. (CVE-2026-4107)

- Stored XSS in the Permissions Based on Mailboxes report. (CVE-2026-27655)

- Stored XSS in the Permissions based on Distribution Groups report. (CVE-2026-28756)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Upgrade ManageEngine Exchange Reporter Plus to build 5802 or later.

See Also

http://www.nessus.org/u?931c8ca8

http://www.nessus.org/u?891fb620

http://www.nessus.org/u?eec8c80a

http://www.nessus.org/u?a9c4a2e6

http://www.nessus.org/u?f4ee0695

http://www.nessus.org/u?9c51c022

http://www.nessus.org/u?202c0a6d

http://www.nessus.org/u?caa4babb

Plugin Details

Severity: Medium

ID: 305773

File Name: manageengine_exchange_reporter_5802.nasl

Version: 1.1

Type: Local

Agent: windows

Family: Windows

Published: 4/9/2026

Updated: 4/9/2026

Supported Sensors: Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: Low

Score: 3.8

CVSS v2

Risk Factor: Medium

Base Score: 5.5

Vector: CVSS2#AV:N/AC:L/Au:S/C:P/I:P/A:N

CVSS Score Source: CVE-2026-4107

CVSS v3

Risk Factor: Medium

Base Score: 5.4

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Vulnerability Information

CPE: cpe:/a:zohocorp:manageengine_exchange_reporter_plus

Required KB Items: installed_sw/ManageEngine Exchange Reporter Plus

Patch Publication Date: 3/19/2026

Vulnerability Publication Date: 3/19/2026

Reference Information

CVE: CVE-2026-27655, CVE-2026-28703, CVE-2026-28754, CVE-2026-28756, CVE-2026-3879, CVE-2026-3880, CVE-2026-4107, CVE-2026-4108