Executive brief
Zirve Nova, a business management and accounting software platform, contains a security vulnerability that could allow an attacker to inject malicious scripts into the application. If exploited, this could lead to unauthorized actions being performed in the context of a user's session or the theft of sensitive session information. However, the attack requires high-level administrative privileges to execute, limiting the potential pool of attackers.
Technical details
A Cross-Site Scripting (XSS) vulnerability exists in Zirve Information Technologies Inc. Zirve Nova versions 235 through 20250131. The flaw stems from CWE-79 (Improper Neutralization of Input During Web Page Generation), allowing an attacker to inject arbitrary web scripts. According to the CVSS vector, the attack is network-reachable and requires high privileges (PR:H) but no user interaction (UI:N). Successful exploitation could impact the confidentiality, integrity, and availability of the application session.
Affected products
- Zirve Information Technologies Inc. Zirve Nova 235 through 20250131
Timeline
- 2025-09-17: advisory: Initial disclosure by TR-CERT/USOM