Horilla has Improper Input Sanitization Leading to XSS and Admin Account Takeover
Vulnerability Description
Horilla is a free and open source Human Resource Management System (HRMS). Prior to version 1.4.0, improper sanitization across the application allows XSS via uploaded SVG (and via allowed <embed>), which can be chained to execute JavaScript whenever users view impacted content (e.g., announcements). This can result in admin account takeover. This issue has been patched in version 1.4.0.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-59525
Credits & Attribution
No credits recorded in the NVD database.
References
More from horilla-opensource
View All →Affected Vendor
horilla-opensource
View all reports →