File Upload Vulnerability in Horilla HRMS Affects Server Security
CVE-2025-59524
7.7HIGH
What is CVE-2025-59524?
Horilla HRMS, an open-source Human Resource Management System, suffers from a serious file upload vulnerability where insecure validation allows attackers to bypass client-side checks. This flaw enables the upload of a malicious executable HTML document, which can execute scripts in the context of an administrator's session, leading to the potential compromise of sensitive information like session cookies. The issue has been addressed in version 1.4.0, emphasizing the importance of always using the latest version to protect against such exploits.
Affected Version(s)
horilla < 1.4.0