Horilla是Horilla公司的一款免费的开源人力资源软件。 Horilla 1.3.0版本存在安全漏洞,该漏洞源于对用户控制的查询参数不安全使用eval函数,可能导致远程代码执行。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| horilla-opensource | horilla | = 1.3.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2025-48869 | 7.5 HIGH | Horilla Unauthorized Access to Candidate Resume Files Due to Broken Access Control |
| CVE-2025-48867 | 4.8 MEDIUM | Horilla Stored Cross-Site Scripting (XSS) Vulnerability in Project and Task Modules |
| CVE-2025-59524 | Horilla Stored XSS Vulnerability via File Upload in Reimbursement Panel | |
| CVE-2025-59525 | Horilla has Improper Input Sanitization Leading to XSS and Admin Account Takeover |
No comments yet