Junglewise Threat Intelligence

CVE-2025-6923: Talent Software UNIS reflected XSS

CVE-2025-6923 · Severity: medium · CVSS 5.4 · Published 2025-12-09

Executive brief

Talent Software UNIS is susceptible to a security flaw that allows attackers to inject malicious scripts into the web interface. This occurs when the application fails to properly clean user-provided data before displaying it back to other users. If an employee clicks a specially crafted link, an attacker could potentially steal login session information or perform unauthorized actions on behalf of the user.

Technical details

A reflected cross-site scripting (XSS) vulnerability exists in Talent Software UNIS versions prior to 42957. The vulnerability is caused by improper neutralization of user-supplied input during web page generation (CWE-79). An unauthenticated remote attacker can exploit this by tricking a user into clicking a malicious link containing a crafted payload. Successful exploitation allows the attacker to execute arbitrary JavaScript in the context of the victim's browser session, potentially leading to session hijacking or unauthorized data access. The vulnerability has been addressed in version 42957.

Affected products

  • Talent Software UNIS before 42957

Timeline

  • 2025-12-09: advisory: Initial publication of CVE-2025-6923

References

Related threats