Executive brief
ZenShare Suite, a business management and document automation platform, is vulnerable to a security flaw in its login page. An attacker could trick a user into clicking a malicious link, allowing the attacker to run unauthorized scripts in the user's web browser. This could lead to the theft of login sessions, sensitive information, or the performance of unauthorized actions on behalf of the user.
Technical details
Multiple reflected cross-site scripting (XSS) vulnerabilities exist in the login.php endpoint of Interzen Consulting S.r.l ZenShare Suite v17.0. The vulnerability is caused by improper neutralization of user-supplied input in the 'codice_azienda' and 'red_url' GET parameters. A remote, unauthenticated attacker can exploit this by enticing a user to visit a specially crafted URL. Successful exploitation allows the execution of arbitrary JavaScript in the victim's browser session, which can be used to hijack sessions or exfiltrate sensitive data. The vendor advisory indicates versions up to and including 17.0 are affected.
Affected products
- Interzen Consulting S.r.l ZenShare Suite 17.0 and earlier
Timeline
- 2026-04-02: advisory: Initial disclosure and NVD publication