cve/2025/CVE-2025-59832.md
2025-09-29 21:09:30 +02:00

960 B
Raw Blame History

CVE-2025-59832

Description

Horilla is a free and open source Human Resource Management System (HRMS). Prior to version 1.4.0, there is a stored XSS vulnerability in the ticket comment editor. A low-privilege authenticated user could run arbitrary JavaScript in an admins browser, exfiltrate the admins cookies/CSRF token, and hijack their session. This issue has been patched in version 1.4.0.

POC

Reference

No PoCs from references.

Github