Horilla

Horilla

17 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.03%
  • Veröffentlicht 24.02.2026 01:16:16
  • Zuletzt bearbeitet 25.02.2026 20:11:23

A flaw has been found in horilla-opensource horilla up to 1.0.2. Impacted is an unknown function of the file static/assets/js/global.js of the component Leads Module. This manipulation of the argument Notes causes cross site scripting. The attack is ...

Exploit
  • EPSS 0.04%
  • Veröffentlicht 24.02.2026 00:32:11
  • Zuletzt bearbeitet 25.02.2026 20:13:39

A vulnerability was detected in horilla-opensource horilla up to 1.0.2. This issue affects the function get of the file horilla_generics/global_search.py of the component Query Parameter Handler. The manipulation of the argument prev_url results in o...

Exploit
  • EPSS 0.01%
  • Veröffentlicht 22.01.2026 03:43:41
  • Zuletzt bearbeitet 29.01.2026 18:47:30

Horilla is a free and open source Human Resource Management System (HRMS). Version 1.4.0 has Improper Access Control, allowing low-privileged employees to self-approve documents they have uploaded. The document-approval UI is intended to be restricte...

Exploit
  • EPSS 0.03%
  • Veröffentlicht 22.01.2026 03:39:06
  • Zuletzt bearbeitet 29.01.2026 18:54:50

Horilla is a free and open source Human Resource Management System (HRMS). In version 1.4.0, the OTP handling logic has a flawed equality check that can be bypassed. When an OTP expires, the server returns None, and if an attacker omits the otp field...

Exploit
  • EPSS 0.01%
  • Veröffentlicht 22.01.2026 03:31:37
  • Zuletzt bearbeitet 29.01.2026 18:56:43

Horilla is a free and open source Human Resource Management System (HRMS). In version 1.4.0, the has_xss() function attempts to block XSS by matching input against a set of regex patterns. However, the regexes are incomplete and context-agnostic, mak...

Exploit
  • EPSS 0.08%
  • Veröffentlicht 22.01.2026 03:21:32
  • Zuletzt bearbeitet 29.01.2026 18:58:16

Horilla is a free and open source Human Resource Management System (HRMS). Versions 1.4.0 and above expose unpublished job postings through the /recruitment/recruitment-details// endpoint without authentication. The response includes draft job titles...

Exploit
  • EPSS 0.01%
  • Veröffentlicht 22.01.2026 02:43:10
  • Zuletzt bearbeitet 29.01.2026 19:02:03

Horilla is a free and open source Human Resource Management System (HRMS). An Improper Access Control vulnerability exists in Horilla HR Software starting in version 1.4.0 and prior to version 1.5.0, allowing any authenticated employee to upload docu...

Exploit
  • EPSS 0.01%
  • Veröffentlicht 22.01.2026 02:41:37
  • Zuletzt bearbeitet 29.01.2026 19:03:50

Horilla is a free and open source Human Resource Management System (HRMS). In versions prior to 1.5.0, a cross-site scripting vulnerability can be triggered because the extension and content-type are not checked during the profile photo update step. ...

Exploit
  • EPSS 0.02%
  • Veröffentlicht 22.01.2026 02:37:19
  • Zuletzt bearbeitet 29.01.2026 20:00:49

Horilla is a free and open source Human Resource Management System (HRMS). A critical File Upload vulnerability in versions prior to 1.5.0, with Social Engineering, allows authenticated users to deploy phishing attacks. By uploading a malicious HTML ...

Exploit
  • EPSS 0.08%
  • Veröffentlicht 25.09.2025 15:16:14
  • Zuletzt bearbeitet 29.09.2025 14:03:20

Horilla is a free and open source Human Resource Management System (HRMS). Prior to version 1.4.0, there is a stored XSS vulnerability in the ticket comment editor. A low-privilege authenticated user could run arbitrary JavaScript in an admin’s brows...