CVE-2026-24034

Horilla is a free and open source Human Resource Management System (HRMS). In versions prior to 1.5.0, a cross-site scripting vulnerability can be triggered because the extension and content-type are not checked during the profile photo update step. Version 1.5.0 fixes the issue.
Configurations

Configuration 1 (hide)

cpe:2.3:a:horilla:horilla:*:*:*:*:*:*:*:*

History

17 Jun 2026, 10:22

Type Values Removed Values Added
Summary
  • (es) Horilla es un Sistema de Gestión de Recursos Humanos (HRMS) de código abierto y gratuito. En versiones anteriores a la 1.5.0, se puede activar una vulnerabilidad de cross-site scripting porque la extensión y el tipo de contenido (content-type) no se verifican durante el paso de actualización de la foto de perfil. La versión 1.5.0 soluciona el problema.

29 Jan 2026, 19:03

Type Values Removed Values Added
First Time Horilla
Horilla horilla
CPE cpe:2.3:a:horilla:horilla:*:*:*:*:*:*:*:*
References () https://github.com/horilla-opensource/horilla/releases/tag/1.5.0 - () https://github.com/horilla-opensource/horilla/releases/tag/1.5.0 - Release Notes
References () https://github.com/horilla-opensource/horilla/security/advisories/GHSA-mvwg-7c8w-qw2p - () https://github.com/horilla-opensource/horilla/security/advisories/GHSA-mvwg-7c8w-qw2p - Exploit, Vendor Advisory

22 Jan 2026, 04:15

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-22 04:15

Updated : 2026-06-17 10:22


NVD link : CVE-2026-24034

Mitre link : CVE-2026-24034

CVE.ORG link : CVE-2026-24034


JSON object : View

Products Affected

horilla

  • horilla
CWE
CWE-434

Unrestricted Upload of File with Dangerous Type