PT-2026-3908 · Horilla · Horilla
Buraksuu
·
Publicado
2026-01-22
·
Atualizado
2026-01-22
·
CVE-2026-24010
CVSS v3.1
8.8
Alta
| Vetor | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Horilla versions prior to 1.5.0
Description
Horilla is a free and open source Human Resource Management System (HRMS). A critical File Upload issue, combined with social engineering techniques, allows authenticated users to launch phishing attacks. An attacker can upload a malicious HTML file, disguised as a profile picture, to create a login page replica that steals user credentials. When a victim accesses the uploaded file URL, they encounter a deceptive "Session Expired" message prompting re-authentication. All entered credentials are then sent to the attacker's server, potentially leading to Account Takeover. The vulnerable functionality involves uploading files, specifically HTML files, which are then served to other users. The API endpoint used for file uploads is not specified. The vulnerable parameter is the file upload field for profile pictures.
Recommendations
Update Horilla to version 1.5.0 or later.
Exploit
Correção
Unrestricted File Upload
Special Elements Injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Horilla