| Vulnerability Details | |
| Severity | High |
| CVE ID | CVE-2025-5366 |
| Affected software versions | Build 5722 and below |
| Fixed version | 5723 |
| Fixed on | June 23, 2025 |
Exchange Reporter Plus was reported to have a security vulnerability in the Folder-wise Read Mails with Subject report. This has been fixed in build 5723, and its release notes can be found here. This has been fixed in build 5723, and its release notes can be found here.
This vulnerability could allow attackers to create a privileged account and gain access to the application.
Given the severity of this vulnerability, customers are strongly advised to update Exchange Reporter Plus to the latest build immediately by following the steps given below,
If you have any questions or need assistance updating the product to the latest version, please contact our product support at support@exchangereporterplus.com.
This vulnerability was discovered by Ngockhanhc311 from FPT NightWolf.