5.4
CVE-2026-24034
- EPSS 0.22%
- Veröffentlicht 22.01.2026 02:41:37
- Zuletzt bearbeitet 29.01.2026 19:03:50
- Quelle security-advisories@github.com
- CVE-Watchlists
- Unerledigt
Horilla has File Upload XSS
Horilla is a free and open source Human Resource Management System (HRMS). In versions prior to 1.5.0, a cross-site scripting vulnerability can be triggered because the extension and content-type are not checked during the profile photo update step. Version 1.5.0 fixes the issue.
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.22% | 0.125 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 5.4 | 2.3 | 2.7 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
|
| security-advisories@github.com | 5.4 | 2.8 | 2.5 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
|
CWE-434 Unrestricted Upload of File with Dangerous Type
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
https://github.com/horilla-opensource/horilla/releases/tag/1.5.0
https://github.com/horilla-opensource/horilla/security/advisories/GHSA-mvwg-7c8w-qw2p