PT-2026-3909 · Horilla · Horilla

Buraksuu

·

Publicado

2026-01-22

·

Atualizado

2026-01-22

·

CVE-2026-24034

CVSS v3.1

5.4

Média

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Horilla versions prior to 1.5.0
Description Horilla is a Human Resource Management System (HRMS). Versions prior to 1.5.0 are susceptible to a cross-site scripting issue. This occurs because the extension and content-type are not validated during the profile photo update process.
Recommendations Update to version 1.5.0 or later.

Exploit

Correção

Unrestricted File Upload

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-24034
GHSA-MVWG-7C8W-QW2P

Produtos afetados

Horilla