CVE-2024-12138

A vulnerability classified as critical was found in horilla up to 1.2.1. This vulnerability affects the function request_new/get_employee_shift/create_reimbursement/key_result_current_value_update/create_meetings/create_skills. The manipulation leads to deserialization. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
References
Link Resource
https://github.com/Sp1d3rL1/horilla-RCE Third Party Advisory Exploit
https://vuldb.com/?ctiid.286858 Permissions Required VDB Entry
https://vuldb.com/?id.286858 Third Party Advisory VDB Entry
https://vuldb.com/?submit.451515 Third Party Advisory VDB Entry
Configurations

Configuration 1 (hide)

cpe:2.3:a:horilla:horilla:*:*:*:*:*:*:*:*

History

19 Sep 2025, 15:32

Type Values Removed Values Added
First Time Horilla horilla
Horilla
References () https://github.com/Sp1d3rL1/horilla-RCE - () https://github.com/Sp1d3rL1/horilla-RCE - Third Party Advisory, Exploit
References () https://vuldb.com/?ctiid.286858 - () https://vuldb.com/?ctiid.286858 - Permissions Required, VDB Entry
References () https://vuldb.com/?id.286858 - () https://vuldb.com/?id.286858 - Third Party Advisory, VDB Entry
References () https://vuldb.com/?submit.451515 - () https://vuldb.com/?submit.451515 - Third Party Advisory, VDB Entry
Summary
  • (es) Se ha detectado una vulnerabilidad clasificada como crítica en horilla hasta la versión 1.2.1. Esta vulnerabilidad afecta a la función request_new/get_employee_shift/create_reimbursement/key_result_current_value_update/create_meetings/create_skills. La manipulación provoca la deserialización. El ataque se puede iniciar de forma remota. El exploit se ha hecho público y puede utilizarse. Se contactó al proveedor con anticipación sobre esta divulgación, pero no respondió de ninguna manera.
CPE cpe:2.3:a:horilla:horilla:*:*:*:*:*:*:*:*

04 Dec 2024, 14:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-12-04 14:15

Updated : 2025-09-19 15:32


NVD link : CVE-2024-12138

Mitre link : CVE-2024-12138

CVE.ORG link : CVE-2024-12138


JSON object : View

Products Affected

horilla

  • horilla
CWE
CWE-20

Improper Input Validation

CWE-502

Deserialization of Untrusted Data