Horilla is a free and open source Human Resource Management System (HRMS). Prior to version 1.4.0, improper sanitization across the application allows XSS via uploaded SVG (and via allowed <embed>), which can be chained to execute JavaScript whenever users view impacted content (e.g., announcements). This can result in admin account takeover. This issue has been patched in version 1.4.0.
References
| Link | Resource |
|---|---|
| https://github.com/Mmo-kali/CVE/blob/main/CVE-2025-59525/2025-08-Horilla_Vulnerability_2.pdf | Exploit Third Party Advisory |
| https://github.com/horilla-opensource/horilla/releases/tag/1.4.0 | Release Notes |
| https://github.com/horilla-opensource/horilla/security/advisories/GHSA-rp5m-vpqr-vpvp | Vendor Advisory Exploit |
Configurations
History
29 Sep 2025, 14:04
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/Mmo-kali/CVE/blob/main/CVE-2025-59525/2025-08-Horilla_Vulnerability_2.pdf - Exploit, Third Party Advisory | |
| References | () https://github.com/horilla-opensource/horilla/releases/tag/1.4.0 - Release Notes | |
| References | () https://github.com/horilla-opensource/horilla/security/advisories/GHSA-rp5m-vpqr-vpvp - Vendor Advisory, Exploit | |
| CPE | cpe:2.3:a:horilla:horilla:*:*:*:*:*:*:*:* | |
| First Time |
Horilla horilla
Horilla |
|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.1 |
24 Sep 2025, 19:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-09-24 19:15
Updated : 2025-09-29 14:04
NVD link : CVE-2025-59525
Mitre link : CVE-2025-59525
CVE.ORG link : CVE-2025-59525
JSON object : View
Products Affected
horilla
- horilla
