PT-2026-21595 · Unknown · Horilla-Opensource
Alexperrakis
·
Published
2026-02-24
·
Updated
2026-02-24
·
CVE-2026-3049
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
horilla-opensource horilla versions up to 1.0.2
Description
A flaw exists in the Query Parameter Handler component of horilla-opensource horilla. Specifically, the
get function within the horilla generics/global search.py file is susceptible to an open redirect condition. Manipulation of the prev url argument can lead to exploitation. The exploit is publicly available.Recommendations
Upgrade to version 1.0.3.
Exploit
Fix
Open Redirect
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Horilla-Opensource