CVE-2025-59525
Horilla is a free and open source Human Resource Management System (HRMS). Prior to version 1.4.0, improper sanitization
Horilla is a free and open source Human Resource Management System (HRMS). Prior to version 1.4.0, improper sanitization across the application allows XSS via uploaded SVG (and via allowed <embed>), which can be chained to execute JavaScript whenever users view impacted content (e.g., announcements). This can result in admin account takeover.
This issue has been patched in version 1.4.0.
MEDIUM · CVSS 6.1
EPSS 0.00038
Schedule remediation
- Public exploit or PoC is available
Sigma rules0
YARA rules0