PT-2026-40245 · Horilla · Horilla
CVE-2026-41513
·
Published
2026-05-12
·
Updated
2026-05-12
CVSS v4.0
4.8
Medium
| Vector | AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N |
Name of the Vulnerable Software and Affected Versions
Horilla version 1.5.0
Description
Notification endpoints trust the unvalidated
next parameter, which allows the redirection of users to arbitrary external URLs. This issue can be leveraged by attackers to transform trusted application links into phishing or social-engineering redirects.Recommendations
Update Horilla to a version newer than 1.5.0.
As a temporary mitigation, restrict or validate the
next parameter in notification endpoints to prevent redirects to external domains.Exploit
Fix
Open Redirect
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Horilla