You're almost there! Please answer a few more questions for access to the Applications content. Complete registration
Interested in joining? Complete your registration by providing Areas of Interest here. Register

URL Security Flaw with Hiring Manager Settings

Received Response
32
Views
2
Comments
edited Dec 14, 2022 6:19AM in Taleo Business Edition (TBE) 2 comments

Summary

URL Security Flaw with Hiring Manager Settings

Content

A hiring manager who has access to his personal requisition was "testing" access points by playing with the URL code within the TBE platform and entered a new number in the URL which brought up a requisition that only another hiring manager or the Administrator would have access to and the requisition was not posted or approved. As a candidate himself, he was able to see candidates within a position he had applied to and can navigate around the system now by plugging in new numbers within the URL that correspond to the requisition numbers posted on our website. This

Howdy, Stranger!

Log In

To view full details, sign in.

Register

Don't have an account? Click here to get started!