CVE-2026-24034

Horilla is a free and open source Human Resource Management System (HRMS). In versions prior to 1.5.0, a cross-site scripting vulnerability can be triggered because the extension and content-type are not checked during the profile photo update step. Version 1.5.0 fixes the issue.
Configurations

Configuration 1 (hide)

cpe:2.3:a:horilla:horilla:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-01-22 04:15

Updated : 2026-01-29 19:03


NVD link : CVE-2026-24034

Mitre link : CVE-2026-24034

CVE.ORG link : CVE-2026-24034


JSON object : View

Products Affected

horilla

  • horilla
CWE
CWE-434

Unrestricted Upload of File with Dangerous Type