CVE-2025-59525
- EPSS 0.03%
- Veröffentlicht 24.09.2025 19:15:42
- Zuletzt bearbeitet 29.09.2025 14:04:23
Horilla is a free and open source Human Resource Management System (HRMS). Prior to version 1.4.0, improper sanitization across the application allows XSS via uploaded SVG (and via allowed <embed>), which can be chained to execute JavaScript whenever...
CVE-2025-59524
- EPSS 0.03%
- Veröffentlicht 24.09.2025 18:15:42
- Zuletzt bearbeitet 29.09.2025 14:04:48
Horilla is a free and open source Human Resource Management System (HRMS). Prior to version 1.4.0, the file upload flow performs validation only in the browser and does not enforce server-side checks. An attacker can bypass the client-side validation...
CVE-2025-48869
- EPSS 0.12%
- Veröffentlicht 24.09.2025 18:15:37
- Zuletzt bearbeitet 29.09.2025 14:05:30
Horilla is a free and open source Human Resource Management System (HRMS). Unauthenticated users can access uploaded resume files in Horilla 1.3.0 by directly guessing or predicting file URLs. These files are stored in a publicly accessible directory...
CVE-2025-48867
- EPSS 0.06%
- Veröffentlicht 24.09.2025 18:15:37
- Zuletzt bearbeitet 29.09.2025 14:06:04
Horilla is a free and open source Human Resource Management System (HRMS). A stored cross-site scripting (XSS) vulnerability in Horilla HRM 1.3.0 allows authenticated admin or privileged users to inject malicious JavaScript payloads into multiple fie...
CVE-2025-48868
- EPSS 0.95%
- Veröffentlicht 24.09.2025 14:15:49
- Zuletzt bearbeitet 29.09.2025 14:06:57
Horilla is a free and open source Human Resource Management System (HRMS). An authenticated Remote Code Execution (RCE) vulnerability exists in Horilla 1.3.0 due to the unsafe use of Python’s eval() function on a user-controlled query parameter in th...
CVE-2025-47789
- EPSS 0.05%
- Veröffentlicht 15.05.2025 19:50:28
- Zuletzt bearbeitet 19.09.2025 15:28:23
Horilla is a free and open source Human Resource Management System (HRMS). In versions up to and including 1.3, an attacker can craft a Horilla URL that refers to an external domain. Upon clicking and logging in, the user is redirected to an external...
CVE-2024-12138
- EPSS 0.12%
- Veröffentlicht 04.12.2024 14:15:19
- Zuletzt bearbeitet 19.09.2025 15:32:38
A vulnerability classified as critical was found in horilla up to 1.2.1. This vulnerability affects the function request_new/get_employee_shift/create_reimbursement/key_result_current_value_update/create_meetings/create_skills. The manipulation leads...