Unauthenticated Access Vulnerability in Horilla Human Resource Management System
CVE-2025-48869

7.5HIGH

Key Information:

Status
Vendor
CVE Published:
24 September 2025

What is CVE-2025-48869?

Horilla is a free and open-source Human Resource Management System (HRMS) that has a security vulnerability allowing unauthenticated users to access sensitive candidate resume files. In version 1.3.0, attackers can exploit this issue by guessing or predicting the URLs of uploaded files that are stored in a publicly accessible directory. This leads to unauthorized retrieval of private information without the need for any authentication. As of the latest information, no patches are available to mitigate this risk.

Affected Version(s)

horilla = 1.3.0

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-48869 : Unauthenticated Access Vulnerability in Horilla Human Resource Management System