ManageEngine (Exchange Reporter Plus) Family June 2025 Security Update Advisory
Overview
Zoho(https://www.zohocorp.com/) has released a security update that addresses a vulnerability in its ManageEngine suite of products. Users of affected products are advised to update to the latest version.
Affected Products
Exchange Reporter Plus build 5722 and earlier
Resolved Vulnerabilities
High Impact Cross Site Scripting (Stored XSS) Vulnerability in Exchange Reporter Plus (CVE-2025-5366) [1]
Vulnerability Patches
Please follow the security advisory posted on June 26 to update to the appropriate version and the latest version.
Exchange Reporter Plus version 5723
Referenced Sites
[1] CVE-2025-5366 – Stored Cross-Site Scripting
https://www.manageengine.com/products/exchange-reports/advisory/CVE-2025-5366.html