Field Validation Capabilities on Oracle Fusion HCM Careers Site
I’m trying to understand what validation or sanitization capabilities the Oracle Fusion HCM Recruiting Careers site currently provides for external candidate‑facing fields such as First Name, Last Name, and other personal‑information inputs.
Specifically, I’m looking to prevent scenarios where a candidate could enter unexpected or malicious text—such as URLs, special characters, or long strings—that might later appear in system‑generated emails and be interpreted as clickable links by email clients. This creates an obvious phishing risk if not mitigated.
One finding flagged by our team recently was this:
- A malicious person navigates to the careers site and begins to apply for a job
0