Cross-Site Scripting in Horilla HR and CRM Software
CVE-2026-71483
8.5HIGH
What is CVE-2026-71483?
Horilla HR and CRM software, in versions before 1.6.0, contains a Cross-Site Scripting (XSS) vulnerability that allows external attackers to exploit the search parameter at /employee/employee-filter-view. This flaw arises due to the lack of HTML neutralization when using jQuery .html() in employee/templates/employee_nav.html. By delivering a crafted link, an attacker can execute malicious JavaScript upon an authenticated user accessing the employee filter, potentially exposing browser-visible session data and enabling unauthorized actions with the victim's application privileges. The issue has been resolved in version 1.6.0.
Affected Version(s)
horilla-hr < 1.6.0
