Horilla is a free and open source Human Resource Management System (HRMS). Prior to version 1.4.0, improper sanitization across the application allows XSS via uploaded SVG (and via allowed <embed>), which can be chained to execute JavaScript whenever users view impacted content (e.g., announcements). This can result in admin account takeover. This issue has been patched in version 1.4.0.
References
Link | Resource |
---|---|
https://github.com/Mmo-kali/CVE/blob/main/CVE-2025-59525/2025-08-Horilla_Vulnerability_2.pdf | Exploit Third Party Advisory |
https://github.com/horilla-opensource/horilla/releases/tag/1.4.0 | Release Notes |
https://github.com/horilla-opensource/horilla/security/advisories/GHSA-rp5m-vpqr-vpvp | Vendor Advisory Exploit |
Configurations
History
29 Sep 2025, 14:04
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:horilla:horilla:*:*:*:*:*:*:*:* | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.1 |
References | () https://github.com/Mmo-kali/CVE/blob/main/CVE-2025-59525/2025-08-Horilla_Vulnerability_2.pdf - Exploit, Third Party Advisory | |
References | () https://github.com/horilla-opensource/horilla/releases/tag/1.4.0 - Release Notes | |
References | () https://github.com/horilla-opensource/horilla/security/advisories/GHSA-rp5m-vpqr-vpvp - Vendor Advisory, Exploit | |
First Time |
Horilla horilla
Horilla |
24 Sep 2025, 19:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-09-24 19:15
Updated : 2025-09-29 14:04
NVD link : CVE-2025-59525
Mitre link : CVE-2025-59525
CVE.ORG link : CVE-2025-59525
JSON object : View
Products Affected
horilla
- horilla