CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2025-3835

CVSS 9.6v3.1pub. 2025-06-09upd. 2025-09-29

Zohocorp ManageEngine Exchange Reporter Plus versions 5721 and prior are vulnerable to Remote code execution in the Content Search module.

🤖 AI Analysis
How it works

The vulnerability classified as CWE-434 (Unrestricted Upload of File with Dangerous Type) indicates that an attacker can upload a file of dangerous type to the Content Search module without proper server-side validation. The network attack vector (AV:N) without authentication requirement (PR:N) means that the exploit can be performed remotely by an unauthorized user, with minimal user interaction required (UI:R). The attack scope extends beyond the application component (S:C), suggesting the possibility of impact on resources outside the directly vulnerable module.

Impact

An attacker can obtain unauthorized remote code execution of arbitrary code on the server, which in practice means the possibility of complete system takeover, data theft, installation of malicious software or further lateral movement in the network.

Mitigation & patch

ManageEngine Exchange Reporter Plus must be updated immediately to a version higher than 5721. Detailed patch instructions are available in the official producer bulletin at: https://www.manageengine.com/products/exchange-reports/advisory/CVE-2025-3835.html

Who is affected

Zohocorp ManageEngine Exchange Reporter Plus in versions 5721 and earlier.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
  • Zohocorp Manageengine Exchange Reporter Plus

    APP
    Zohocorp
    5.7< 5.7
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
RCE
CWE
References

Related vulnerabilities

CVE-2020-24786CRITICAL9.8PL ✓same product

Authentication bypass w wielu produktach Zoho ManageEngine

CVE-2026-28754HIGH7.3same product

Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Distribution...

CVE-2026-28703HIGH7.3same product

Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Mails Exchan...

CVE-2026-27655HIGH7.3same product

Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Permissions ...

CVE-2026-28756HIGH7.3same product

Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Permissions ...