Zohocorp ManageEngine Exchange Reporter Plus versions 5721 and prior are vulnerable to Remote code execution in the Content Search module.
The vulnerability classified as CWE-434 (Unrestricted Upload of File with Dangerous Type) indicates that an attacker can upload a file of dangerous type to the Content Search module without proper server-side validation. The network attack vector (AV:N) without authentication requirement (PR:N) means that the exploit can be performed remotely by an unauthorized user, with minimal user interaction required (UI:R). The attack scope extends beyond the application component (S:C), suggesting the possibility of impact on resources outside the directly vulnerable module.
An attacker can obtain unauthorized remote code execution of arbitrary code on the server, which in practice means the possibility of complete system takeover, data theft, installation of malicious software or further lateral movement in the network.
ManageEngine Exchange Reporter Plus must be updated immediately to a version higher than 5721. Detailed patch instructions are available in the official producer bulletin at: https://www.manageengine.com/products/exchange-reports/advisory/CVE-2025-3835.html
Zohocorp ManageEngine Exchange Reporter Plus in versions 5721 and earlier.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:HZohocorp Manageengine Exchange Reporter Plus
APPZohocorp5.7< 5.7
Related vulnerabilities
Authentication bypass w wielu produktach Zoho ManageEngine
Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Distribution...
Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Mails Exchan...
Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Permissions ...
Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Permissions ...