Unauthenticated Access Vulnerability in Horilla Human Resource Management System
CVE-2025-48869
7.5HIGH
What is CVE-2025-48869?
Horilla is a free and open-source Human Resource Management System (HRMS) that has a security vulnerability allowing unauthenticated users to access sensitive candidate resume files. In version 1.3.0, attackers can exploit this issue by guessing or predicting the URLs of uploaded files that are stored in a publicly accessible directory. This leads to unauthorized retrieval of private information without the need for any authentication. As of the latest information, no patches are available to mitigate this risk.
Affected Version(s)
horilla = 1.3.0