5.3
/ 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Description
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in TalentSoft Software e-BAP Automation allows Cross-Site Scripting (XSS).This issue affects e-BAP Automation: from 1.8.96 before v.41815.
Basic Information
ID
CVE-2025-10876
Source
TR-CERT
Published
Dec 9, 2025 at 13:49
Affected Product
Vendor
TalentSoft Software
Product
e-BAP Automation
Version
1.8.96
Affected Versions
TalentSoft Software e-BAP Automation 1.8.96