Horilla is a free and open source Human Resource Management System (HRMS). Prior to version 1.4.0, improper sanitization across the application allows XSS via uploaded SVG (and via allowed <embed>), which can be chained to execute JavaScript whenever users view impacted content (e.g., announcements). This can result in admin account takeover. This issue has been patched in version 1.4.0.
References
| Link | Resource |
|---|---|
| https://github.com/Mmo-kali/CVE/blob/main/CVE-2025-59525/2025-08-Horilla_Vulnerability_2.pdf | Exploit Third Party Advisory |
| https://github.com/horilla-opensource/horilla/releases/tag/1.4.0 | Release Notes |
| https://github.com/horilla-opensource/horilla/security/advisories/GHSA-rp5m-vpqr-vpvp | Vendor Advisory Exploit |
Configurations
History
No history.
Information
Published : 2025-09-24 19:15
Updated : 2025-09-29 14:04
NVD link : CVE-2025-59525
Mitre link : CVE-2025-59525
CVE.ORG link : CVE-2025-59525
JSON object : View
Products Affected
horilla
- horilla
