PT-2026-3913 · Horilla · Horilla

Whoisshuvam

·

Published

2026-01-22

·

Updated

2026-01-29

·

CVE-2026-24037

CVSS v3.1
5.4
VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Horilla versions prior to 1.5.0
Description Horilla is a Human Resource Management System (HRMS). The
has xss()
function in version 1.4.0 attempts to prevent Cross-Site Scripting (XSS) by using regular expressions to filter input. However, these regular expressions are insufficient and do not consider the context of the input, allowing attackers to bypass the filtering mechanism. Successful exploitation can lead to redirecting users to malicious domains, executing external JavaScript, and stealing Cross-Site Request Forgery (CSRF) tokens. These stolen tokens can then be used to perform Cross-Site Request Forgery attacks against administrators.
Recommendations Horilla versions prior to 1.5.0 should be updated to version 1.5.0 or later.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2026-24037
GHSA-RQW5-FJM4-RGVM

Affected Products

Horilla