CVE-2024-4657
Talent BAP Automation Cross-Site Scripting Vulnerability.
Halo Surface Signal: 4 out of 5 — likely to be public-facing.
A vulnerability in the BAP Automation web application allows for the injection of malicious scripts, potentially leading to unauthorized access to data and systems. This stored cross-site scripting (XSS) flaw enables attackers to execute code within a user's browser, which can result in session hijacking or further pri