Junglewise Threat Intelligence

CVE-2025-6924: Talent Software e-BAP Automation Reflected XSS

CVE-2025-6924 · Severity: medium · CVSS 5.4 · Published 2025-12-09

Executive brief

Talent Software e-BAP Automation, a business process automation platform, is vulnerable to a security flaw that could allow attackers to execute malicious scripts in a user's browser. This occurs when a user clicks a specially crafted link, potentially leading to unauthorized actions being performed on the user's behalf or the theft of sensitive session information. Organizations should update to version 42957 or later to mitigate this risk.

Technical details

A Reflected Cross-Site Scripting (XSS) vulnerability exists in Talent Software e-BAP Automation due to improper neutralization of user-supplied input during web page generation (CWE-79). The vulnerability allows a remote, unauthenticated attacker to inject malicious JavaScript into a victim's browser session by tricking them into clicking a malicious link. Successful exploitation requires user interaction and can result in the execution of arbitrary script code in the context of the victim's browser, potentially leading to session hijacking or unauthorized data access. The issue is resolved in version 42957.

Affected products

  • Talent Software e-BAP Automation before 42957

Timeline

  • 2025-12-09: advisory: Initial disclosure by TR-CERT (USOM)

References

Related threats