CVE-2026-24034

Horilla is a free and open source Human Resource Management System (HRMS). In versions prior to 1.5.0, a cross-site scripting vulnerability can be triggered because the extension and content-type are not checked during the profile photo update step. Version 1.5.0 fixes the issue.
Configurations

Configuration 1 (hide)

cpe:2.3:a:horilla:horilla:*:*:*:*:*:*:*:*

History

29 Jan 2026, 19:03

Type Values Removed Values Added
First Time Horilla
Horilla horilla
CPE cpe:2.3:a:horilla:horilla:*:*:*:*:*:*:*:*
References () https://github.com/horilla-opensource/horilla/releases/tag/1.5.0 - () https://github.com/horilla-opensource/horilla/releases/tag/1.5.0 - Release Notes
References () https://github.com/horilla-opensource/horilla/security/advisories/GHSA-mvwg-7c8w-qw2p - () https://github.com/horilla-opensource/horilla/security/advisories/GHSA-mvwg-7c8w-qw2p - Exploit, Vendor Advisory

22 Jan 2026, 04:15

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-22 04:15

Updated : 2026-01-29 19:03


NVD link : CVE-2026-24034

Mitre link : CVE-2026-24034

CVE.ORG link : CVE-2026-24034


JSON object : View

Products Affected

horilla

  • horilla
CWE
CWE-434

Unrestricted Upload of File with Dangerous Type