CVE-2019-18205: Zucchetti Infobusiness
Medium severity, CVSS 6.1. EPSS: 0.7% chance of exploitation in the next 30 days.
Multiple Reflected Cross-site Scripting (XSS) vulnerabilities exist in Zucchetti InfoBusiness before and including 4.4.1. The browsing component did not properly sanitize user input (encoded in base64). This also applies to the search functionality for the searchKey parameter.
Affected products
- Zucchetti Infobusiness: up to and including 4.4.1
Published 2019-10-30. Last modified 2026-06-17.