Open Source Human Resource Management System Vulnerability in Horilla
CVE-2025-47789

6.1MEDIUM

Key Information:

Status
Vendor
CVE Published:
15 May 2025

What is CVE-2025-47789?

Horilla, an open source Human Resource Management System, contains a vulnerability that enables attackers to craft URLs leading to external domains. Users clicking these URLs, particularly after logging in, are redirected to potentially malicious websites. This redirection can facilitate phishing attacks or impersonation, compromising user security and trust in the Horilla platform. The issue has been addressed in commit 1c72404df6888bb23af73c767fdaee5e6679ebd6 to safeguard users against such threats.

Affected Version(s)

horilla <= 1.3

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.