Redirect Vulnerability in Horilla HR and CRM Software
CVE-2026-41513
4.8MEDIUM
What is CVE-2026-41513?
Horilla HR and CRM Software version 1.5.0 contains a security flaw where the notification endpoints do not adequately validate the 'next' parameter, enabling attackers to redirect users to untrusted external URLs. This weakness permits the exploitation of trusted application links, potentially leading to phishing attacks and social engineering threats, as users may be misled into visiting malicious sites under the guise of legitimate notifications.
Affected Version(s)
horilla-hr <= 1.5.0
