PT-2026-3912 · Horilla · Horilla

Whoisshuvam

·

Published

2026-01-22

·

Updated

2026-01-22

·

CVE-2026-24036

CVSS v3.1
5.3
VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Horilla versions 1.4.0 through 1.4.9
Description Horilla, a Human Resource Management System (HRMS), has an issue where unpublished job postings are exposed. This occurs through the ''/recruitment/recruitment-details//'' endpoint without requiring authentication. The response includes draft job titles, descriptions, and the application link, allowing unauthenticated users to view unpublished roles and access the application workflow. This unauthorized access can lead to the leakage of sensitive internal hiring information and candidate confusion.
Recommendations Update to version 1.5.0 or later.

Exploit

Fix

Improper Access Control

Weakness Enumeration

Related Identifiers

CVE-2026-24036
GHSA-Q4XR-W96P-3VG7

Affected Products

Horilla