Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2026-30252 — The ZenShare Suite application is vulnerable by a Reflected Cross-Site Scripting (XSS) vulnerability, affecting web application login and recovery password functionalities. | Kitploit
Tools/GitHubGitHub/venablee/cve-2026-30252
Vulnerability AnalysisExploitationWeb SecurityPapers & ResearchLearning & Education
GitHubvenablee/cve-2026-30252

CVE-2026-30252

The ZenShare Suite application is vulnerable by a Reflected Cross-Site Scripting (XSS) vulnerability, affecting web application login and recovery password functionalities.

View Repository
1 day agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

ZenShare Suite - Vulnerability Disclosure

This repository contains details regarding multiple Reflected Cross-Site Scripting (XSS) vulnerabilities discovered in the ZenShare Suite application.

Vulnerability Overview

The ZenShare Suite application is vulnerable to Reflected Cross-Site Scripting (XSS) affecting the login and password recovery functionalities. An attacker can exploit these issues by crafting a malicious URL and tricking a victim into visiting it, leading to the execution of arbitrary JavaScript code in the victim’s browser.


[CVE-2026-30252]

Description

Multiple reflected cross-site scripting (XSS) vulnerabilities in the login.php endpoint of Interzen Consulting S.r.l ZenShare Suite v17.0 allows attackers to execute arbitrary Javascript in the context of the user's browser via a crafted URL injected into the codice_azienda and red_url parameters.

Details

  • Vulnerability Type: Cross Site Scripting (XSS)
  • Affected Component: login.php
  • Vulnerable Parameters: codice_azienda, (GET)
red_url
  • Attack Vector: Remote
  • Impact: Javascript Client-Side Code Execution

  • Affected Versions

    • Product: ZenShare Suite
    • Version: < 17.0
    • Vendor: Interzen Consulting S.r.l
    Download Tool