Junglewise Threat Intelligence

CVE-2025-10876: Talent Software e-BAP Automation XSS

CVE-2025-10876 · Severity: medium · CVSS 5.3 · Published 2025-12-09

Executive brief

Talent Software e-BAP Automation, a platform used for business process automation, contains a security vulnerability that allows for cross-site scripting. An attacker could exploit this to inject malicious scripts into the web interface, potentially leading to the theft of user session information or unauthorized actions on behalf of legitimate users. This could compromise the integrity of the automation platform and the data it manages.

Technical details

A Cross-Site Scripting (XSS) vulnerability exists in Talent Software e-BAP Automation versions 1.8.96 through v.41815. The flaw stems from CWE-79 (Improper Neutralization of Input During Web Page Generation), where the application fails to properly sanitize user-supplied input before rendering it in the browser. A remote, unauthenticated attacker can exploit this over the network to execute arbitrary JavaScript in the context of a victim's browser session. This can lead to information disclosure, such as session token theft. The vulnerability is addressed in version v.41815.

Affected products

  • Talent Software e-BAP Automation From 1.8.96 before v.41815

Timeline

  • 2025-12-09: disclosed
  • 2025-12-09: advisory

References

Related threats