File Upload Vulnerability in Horilla HRMS Affects Server Security
CVE-2025-59524
What is CVE-2025-59524?
Horilla HRMS, an open-source Human Resource Management System, suffers from a serious file upload vulnerability where insecure validation allows attackers to bypass client-side checks. This flaw enables the upload of a malicious executable HTML document, which can execute scripts in the context of an administrator's session, leading to the potential compromise of sensitive information like session cookies. The issue has been addressed in version 1.4.0, emphasizing the importance of always using the latest version to protect against such exploits.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
horilla < 1.4.0
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
