CVE Database
/

CVE-2025-59525

Back to search

CVE-2025-59525

Published: Sep 24, 2025

Modified: Oct 15, 2025

PUBLISHED

Description

Horilla is a free and open source Human Resource Management System (HRMS). Prior to version 1.4.0, improper sanitization across the application allows XSS via uploaded SVG (and via allowed <embed>), which can be chained to execute JavaScript whenever users view impacted content (e.g., announcements). This can result in admin account takeover. This issue has been patched in version 1.4.0.

VendorProductVersions

horilla-opensource

horilla

affected
< 1.4.0

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now
CVE-2025-59525 - Security Vulnerability | QwikSec