๐Ÿ” CVE Alert

CVE-2025-0419

MEDIUM 4.7

XSS in Mikrogrup's Zirve Nova

CVSS Score
4.7
EPSS Score
0.1%
EPSS Percentile
20th

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Zirve Information Technologies Inc. Zirve Nova allows Cross-Site Scripting (XSS). This issue affects Zirve Nova: from 235 through 20250131.

CWE CWE-79
Vendor zirve information technologies inc.
Product zirve nova
Published Sep 17, 2025
Last Updated Jun 6, 2026
Stay Ahead of the Next One

Get instant alerts for zirve information technologies inc. zirve nova

Be the first to know when new medium vulnerabilities affecting zirve information technologies inc. zirve nova are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L
Attack Vector
Network
Attack Complexity
Low
Privileges Required
High
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
Low
Availability
Low

Affected Versions

Zirve Information Technologies Inc. / Zirve Nova
235 โ‰ค 20250131

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
usom.gov.tr: https://www.usom.gov.tr/bildirim/tr-25-0260 siberguvenlik.gov.tr: https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-25-0260

Credits

Berat ARSLAN