PT-2026-3914 · Horilla · Horilla

Whoisshuvam

·

Published

2026-01-22

·

Updated

2026-01-27

·

CVE-2026-24038

CVSS v3.1
8.1
VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Horilla version 1.4.0
Description Horilla, a Human Resource Management System (HRMS), contains a flaw in its two-factor authentication implementation. Specifically, the OTP handling logic has a flawed equality check. When an OTP expires, the server returns None. An attacker can bypass two-factor authentication by omitting the
otp
field from their POST request, causing the comparison
user otp == otp
to pass, even without a valid OTP. Targeting administrative accounts could lead to compromise of sensitive HR data and manipulation of employee records. The vulnerable parameter is
otp
.
Recommendations Update to version 1.5.0 or later.

Exploit

Fix

Improper Authentication

Weakness Enumeration

Related Identifiers

CVE-2026-24038
GHSA-HQPV-FF5V-3HWF

Affected Products

Horilla