PT-2026-3913 · Horilla · Horilla
Whoisshuvam
·
Published
2026-01-22
·
Updated
2026-01-29
·
CVE-2026-24037
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Horilla versions prior to 1.5.0
Description
Horilla is a Human Resource Management System (HRMS). The
has xss() function in version 1.4.0 attempts to prevent Cross-Site Scripting (XSS) by using regular expressions to filter input. However, these regular expressions are insufficient and do not consider the context of the input, allowing attackers to bypass the filtering mechanism. Successful exploitation can lead to redirecting users to malicious domains, executing external JavaScript, and stealing Cross-Site Request Forgery (CSRF) tokens. These stolen tokens can then be used to perform Cross-Site Request Forgery attacks against administrators.Recommendations
Horilla versions prior to 1.5.0 should be updated to version 1.5.0 or later.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Horilla