Hello everybody!
We are glad to announce the release of Exchange Reporter Plus' latest build–5723.
Security fix:
The following stored XSS vulnerabilities in the Reports module have been fixed.
CVE-2025-5366, as reported by Ngockhanhc311 from FPT NightWolf through our bug bounty program.
A path traversal vulnerability in the Schedule Reports module caused by allowing invalid characters in the Schedule Name field when creating a new scheduled report has been fixed.
A vulnerability where the product's Redis server lacked authentication, allowing unauthorized access to stored data, has been fixed.
A vulnerability that allowed unauthorized technicians to update mail and SMS Server settings has been fixed.
How to update?
Update using service pack.
New to Exchange Reporter Plus?
Download the fully functional free trial now.
Regards,
Exchange Reporter Plus Team
Email: support@exchangereporterplus.com