CVE-2026-24034
EUVD-2026-421422.01.2026, 04:15
Horilla is a free and open source Human Resource Management System (HRMS). In versions prior to 1.5.0, a cross-site scripting vulnerability can be triggered because the extension and content-type are not checked during the profile photo update step. Version 1.5.0 fixes the issue.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| horilla | horilla | 𝑥 < 1.5.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration