CVE-2026-30252

MEDIUM

ZenShare Suite 17.0 - Reflected XSS

Title source: llm

Description

Multiple reflected cross-site scripting (XSS) vulnerabilities in the login.php endpoint of Interzen Consulting S.r.l ZenShare Suite v17.0 allows attackers to execute arbitrary Javascript in the context of the user's browser via a crafted URL injected into the codice_azienda and red_url parameters.

Scores

CVSS v3 6.1
EPSS 0.0003
EPSS Percentile 9.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (4)
interzen/zencrm 17.0
interzen/zenhr 17.0
interzen/zenproject 17.0
interzen/zenpurchase 17.0
Published Apr 02, 2026
Tracked Since Apr 03, 2026