Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Talent Software UNIS allows Reflected XSS.

This issue affects UNIS: before 28376.

Project Subscriptions

Vendors Products
Talentyazilim Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2023-12385 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Talent Software UNIS allows Reflected XSS.This issue affects UNIS: before 28376.
Fixes

Solution

Update the software version to >=28376


Workaround

No workaround given by the vendor.

History

Mon, 01 Jun 2026 13:00:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Talent Software UNIS allows Reflected XSS.This issue affects UNIS: before 28376. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Talent Software UNIS allows Reflected XSS. This issue affects UNIS: before 28376.
Title XSS in Talent Software UNIS XSS in Talent Software UNIS
References

Tue, 04 Mar 2025 03:45:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: TR-CERT

Published:

Updated: 2026-06-01T12:02:55.092Z

Reserved: 2023-01-16T13:03:38.488Z

Link: CVE-2023-0322

cve-icon Vulnrichment

Updated: 2024-08-02T05:10:55.145Z

cve-icon NVD

Status : Modified

Published: 2023-03-15T12:15:10.007

Modified: 2026-06-01T13:16:19.360

Link: CVE-2023-0322

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses