Junglewise Threat Intelligence

CVE-2025-0419: Zirve Information Technologies Zirve Nova XSS

CVE-2025-0419 · Severity: medium · CVSS 4.7 · Published 2025-09-17

Executive brief

Zirve Nova, a business management and accounting software platform, contains a security vulnerability that could allow an attacker to inject malicious scripts into the application. If exploited, this could lead to unauthorized actions being performed in the context of a user's session or the theft of sensitive session information. However, the attack requires high-level administrative privileges to execute, limiting the potential pool of attackers.

Technical details

A Cross-Site Scripting (XSS) vulnerability exists in Zirve Information Technologies Inc. Zirve Nova versions 235 through 20250131. The flaw stems from CWE-79 (Improper Neutralization of Input During Web Page Generation), allowing an attacker to inject arbitrary web scripts. According to the CVSS vector, the attack is network-reachable and requires high privileges (PR:H) but no user interaction (UI:N). Successful exploitation could impact the confidentiality, integrity, and availability of the application session.

Affected products

  • Zirve Information Technologies Inc. Zirve Nova 235 through 20250131

Timeline

  • 2025-09-17: advisory: Initial disclosure by TR-CERT/USOM

References