Executive brief
A vulnerability has been identified in the Zirve Information Technologies E-Taxpayer Accounting Website, a platform used for managing tax and accounting data. This flaw allows attackers to inject malicious scripts into the website, which could lead to the theft of session cookies, unauthorized access to taxpayer accounts, or the manipulation of displayed information. If exploited, this could compromise sensitive financial data and damage the organization's reputation for data security.
Technical details
A Reflected Cross-Site Scripting (XSS) vulnerability exists in the Zirve Information Technologies E-Taxpayer Accounting Website through version 07082025. The flaw is caused by the improper neutralization of user-supplied input during web page generation (CWE-79). An unauthenticated remote attacker can exploit this by tricking a user into clicking a specially crafted link, allowing the execution of arbitrary JavaScript in the context of the victim's browser session. This can result in session hijacking, unauthorized data modification, or information disclosure. The vulnerability is reachable over the network without prior authentication.
Affected products
- Zirve Information Technologies Inc. E-Taxpayer Accounting Website through 07082025
Timeline
- 2026-02-09: advisory: Initial publication of the CVE record