CVE-2026-30252
EUVD-2026-1855002.04.2026, 21:16
Multiple reflected cross-site scripting (XSS) vulnerabilities in the login.php endpoint of Interzen Consulting S.r.l ZenShare Suite v17.0 allows attackers to execute arbitrary Javascript in the context of the user's browser via a crafted URL injected into the codice_azienda and red_url parameters.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| interzen | zencrm | 17.0 |
| interzen | zenhr | 17.0 |
| interzen | zenproject | 17.0 |
| interzen | zenpurchase | 17.0 |
𝑥
= Vulnerable software versions