PT-2025-39264 · Horilla · Horilla

Naklehzeidan21

·

Published

2025-09-24

·

Updated

2025-09-29

·

CVE-2025-48868

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Horilla versions prior to 1.3.1
Description Horilla is a free and open source Human Resource Management System (HRMS). An authenticated Remote Code Execution (RCE) issue exists due to the unsafe use of Python’s eval() function on a user-controlled query parameter in the project bulk archive view. This allows privileged users, such as administrators, to execute arbitrary system commands on the server. Exploitation is possible even when Django’s DEBUG mode is set to False, by using blind payloads like a reverse shell, resulting in full remote code execution.
Recommendations Update to version 1.3.1 or later.

Exploit

Fix

RCE

Eval Injection

Weakness Enumeration

Related Identifiers

CVE-2025-48868
GHSA-H6QJ-PWMX-WJHW

Affected Products

Horilla