Hello everybody!
Security fix:
The following vulnerabilities, as reported by Ngockhanhc311 from FPT NightWolf through our bug bounty program, has been fixed:
CVE-2025-3835: A path traversal vulnerability in the Content Search module where malicious attachment file names caused the attachment to be downloaded outside the intended directory.
A stored XSS vulnerability while viewing mail attachments from search results in the Content Search module.
A ReDoS vulnerability that was caused by the usage of complex RegEx patterns in the search input within the Content Search module.
A vulnerability where the attachments downloaded through the Content Search module were accessible through unauthenticated URLs.
How to update?
Update using service pack.
New to Exchange Reporter Plus?
Download the fully functional free trial now.
Regards,
Exchange Reporter Plus Team
Email: support@exchangereporterplus.com