Horilla is a free and open source Human Resource Management System (HRMS). In 1.5.0, an insecure direct object reference in the employee document viewer allows any authenticated user to access other employees’ uploaded documents by changing the document ID in the request. This exposes sensitive HR files such as identity documents, contracts, certificates, and other private employee records.
CVSS
No CVSS.
References
Configurations
No configuration.
History
21 Apr 2026, 19:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-04-21 19:16
Updated : 2026-04-22 21:05
NVD link : CVE-2026-40865
Mitre link : CVE-2026-40865
CVE.ORG link : CVE-2026-40865
JSON object : View
Products Affected
No product.
