PT-2026-3912 · Horilla · Horilla

Whoisshuvam

·

Publicado

2026-01-22

·

Atualizado

2026-01-22

·

CVE-2026-24036

CVSS v3.1

5.3

Média

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Horilla versions 1.4.0 through 1.4.9
Description Horilla, a Human Resource Management System (HRMS), has an issue where unpublished job postings are exposed. This occurs through the ''/recruitment/recruitment-details//'' endpoint without requiring authentication. The response includes draft job titles, descriptions, and the application link, allowing unauthenticated users to view unpublished roles and access the application workflow. This unauthorized access can lead to the leakage of sensitive internal hiring information and candidate confusion.
Recommendations Update to version 1.5.0 or later.

Exploit

Correção

Improper Access Control

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-24036
GHSA-Q4XR-W96P-3VG7

Produtos afetados

Horilla