4.7
/ 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L
Description
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Zirve Informatics Zirve Nova allows Cross-Site Scripting (XSS).This issue affects Zirve Nova: from 235 through 20250131.
Basic Information
ID
CVE-2025-0419
Source
TR-CERT
Published
Sep 17, 2025 at 08:20
Modified
Sep 17, 2025 at 08:52
Affected Product
Vendor
Zirve Informatics
Product
Zirve Nova
Version
235
Affected Versions
Zirve Informatics Zirve Nova 235