PT-2026-3914 · Horilla · Horilla

Whoisshuvam

·

Publicado

2026-01-22

·

Atualizado

2026-01-27

·

CVE-2026-24038

CVSS v3.1

8.1

Alta

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Horilla version 1.4.0
Description Horilla, a Human Resource Management System (HRMS), contains a flaw in its two-factor authentication implementation. Specifically, the OTP handling logic has a flawed equality check. When an OTP expires, the server returns None. An attacker can bypass two-factor authentication by omitting the otp field from their POST request, causing the comparison user otp == otp to pass, even without a valid OTP. Targeting administrative accounts could lead to compromise of sensitive HR data and manipulation of employee records. The vulnerable parameter is otp.
Recommendations Update to version 1.5.0 or later.

Exploit

Correção

Improper Authentication

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-24038
GHSA-HQPV-FF5V-3HWF

Produtos afetados

Horilla