Interzen Consulting ZenShare Suite Reflected Cross-Site Scripting Vulnerability

Vulnerability

A reflected cross-site scripting vulnerability has been identified in the login.php endpoint of Interzen Consulting S.r.l ZenShare Suite version 17.0. This vulnerability allows attackers to execute arbitrary JavaScript in the context of the user's browser. The issue arises from crafted URLs injected into the codice_azienda and red_url parameters.

Impact

Exploitation of this vulnerability allows for the execution of arbitrary JavaScript in the victim's browser, potentially leading to unauthorized actions or data exposure.

Added: Apr 2, 2026, 9:49 PM
Updated: Apr 2, 2026, 9:49 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
1.7
exploitability
6.2
remediation
0.0
relevance
5.1
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.