Executive brief
Talent Software e-BAP Automation, a business process automation platform, is vulnerable to a security flaw that could allow attackers to execute malicious scripts in a user's browser. This occurs when a user clicks a specially crafted link, potentially leading to unauthorized actions being performed on the user's behalf or the theft of sensitive session information. Organizations should update to version 42957 or later to mitigate this risk.
Technical details
A Reflected Cross-Site Scripting (XSS) vulnerability exists in Talent Software e-BAP Automation due to improper neutralization of user-supplied input during web page generation (CWE-79). The vulnerability allows a remote, unauthenticated attacker to inject malicious JavaScript into a victim's browser session by tricking them into clicking a malicious link. Successful exploitation requires user interaction and can result in the execution of arbitrary script code in the context of the victim's browser, potentially leading to session hijacking or unauthorized data access. The issue is resolved in version 42957.
Affected products
- Talent Software e-BAP Automation before 42957
Timeline
- 2025-12-09: advisory: Initial disclosure by TR-CERT (USOM)