Multiple reflected cross-site scripting (XSS) vulnerabilities in the login.php endpoint of Interzen Consulting S.r.l ZenShare Suite v17.0 allows attackers to execute arbitrary Javascript in the context of the user's browser via a crafted URL injected into the codice_azienda and red_url parameters.
Attack Parameters
Impact Assessment
CVSS Vector v3.1
Weakness Type (CWE)
Vulnerable Products 4
| Configuration | From (including) | Up to (excluding) |
|---|---|---|
|
Interzen Zencrm
cpe:2.3:a:interzen:zencrm:17.0:*:*:*:*:*:*:*
|
— | — |
|
Interzen Zenhr
cpe:2.3:a:interzen:zenhr:17.0:*:*:*:*:*:*:*
|
— | — |
|
Interzen Zenproject
cpe:2.3:a:interzen:zenproject:17.0:*:*:*:*:*:*:*
|
— | — |
|
Interzen Zenpurchase
cpe:2.3:a:interzen:zenpurchase:17.0:*:*:*:*:*:*:*
|
— | — |