Horilla is a free and open source Human Resource Management System (HRMS). In versions prior to 1.5.0, a cross-site scripting vulnerability can be triggered because the extension and content-type are not checked during the profile photo update step. Version 1.5.0 fixes the issue.
References
| Link | Resource |
|---|---|
| https://github.com/horilla-opensource/horilla/releases/tag/1.5.0 | Release Notes |
| https://github.com/horilla-opensource/horilla/security/advisories/GHSA-mvwg-7c8w-qw2p | Exploit Vendor Advisory |
Configurations
History
29 Jan 2026, 19:03
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Horilla
Horilla horilla |
|
| CPE | cpe:2.3:a:horilla:horilla:*:*:*:*:*:*:*:* | |
| References | () https://github.com/horilla-opensource/horilla/releases/tag/1.5.0 - Release Notes | |
| References | () https://github.com/horilla-opensource/horilla/security/advisories/GHSA-mvwg-7c8w-qw2p - Exploit, Vendor Advisory |
22 Jan 2026, 04:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-01-22 04:15
Updated : 2026-01-29 19:03
NVD link : CVE-2026-24034
Mitre link : CVE-2026-24034
CVE.ORG link : CVE-2026-24034
JSON object : View
Products Affected
horilla
- horilla
CWE
CWE-434
Unrestricted Upload of File with Dangerous Type
