CVE-2026-24010

Horilla is a free and open source Human Resource Management System (HRMS). A critical File Upload vulnerability in versions prior to 1.5.0, with Social Engineering, allows authenticated users to deploy phishing attacks. By uploading a malicious HTML file disguised as a profile picture, an attacker can create a convincing login page replica that steals user credentials. When a victim visits the uploaded file URL, they see an authentic-looking "Session Expired" message prompting them to re-authenticate. All entered credentials are captured and sent to the attacker's server, enabling Account Takeover. Version 1.5.0 patches the issue.
Configurations

Configuration 1 (hide)

cpe:2.3:a:horilla:horilla:*:*:*:*:*:*:*:*

History

29 Jan 2026, 20:00

Type Values Removed Values Added
References () https://github.com/horilla-opensource/horilla/releases/tag/1.5.0 - () https://github.com/horilla-opensource/horilla/releases/tag/1.5.0 - Release Notes
References () https://github.com/horilla-opensource/horilla/security/advisories/GHSA-5jfv-gw8w-49h3 - () https://github.com/horilla-opensource/horilla/security/advisories/GHSA-5jfv-gw8w-49h3 - Exploit, Vendor Advisory
CVSS v2 : unknown
v3 : 8.8
v2 : unknown
v3 : 8.0
First Time Horilla
Horilla horilla
CWE CWE-434
CPE cpe:2.3:a:horilla:horilla:*:*:*:*:*:*:*:*

22 Jan 2026, 03:15

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-22 03:15

Updated : 2026-01-29 20:00


NVD link : CVE-2026-24010

Mitre link : CVE-2026-24010

CVE.ORG link : CVE-2026-24010


JSON object : View

Products Affected

horilla

  • horilla
CWE
CWE-74

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

CWE-474

Use of Function with Inconsistent Implementations

CWE-434

Unrestricted Upload of File with Dangerous Type