
Reflected XSS vulnerability disclosure for ZenShare Suite login_newpwd.php, allowing arbitrary JavaScript execution via crafted URL in codice_azienda parameter.
This repository contains details regarding multiple Reflected Cross-Site Scripting (XSS) vulnerabilities discovered in the ZenShare Suite application.
The ZenShare Suite application is vulnerable to Reflected Cross-Site Scripting (XSS) affecting the login and password recovery functionalities. An attacker can exploit these issues by crafting a malicious URL and tricking a victim into visiting it, leading to the execution of arbitrary JavaScript code in the victim’s browser.
A reflected cross-site scripting (XSS) vulnerability in the login_newpwd.php endpoint of Interzen Consulting S.r.l ZenShare Suite v17.0 allows attackers to execute arbitrary Javascript in the context of the user's browser via a crafted URL injected into the codice_azienda parameter.
login_newpwd.phpcodice_azienda (GET)