CVE-2025-48869

Horilla is a free and open source Human Resource Management System (HRMS). Unauthenticated users can access uploaded resume files in Horilla 1.3.0 by directly guessing or predicting file URLs. These files are stored in a publicly accessible directory, allowing attackers to retrieve sensitive candidate information without authentication. At time of publication there is no known patch.
Configurations

Configuration 1 (hide)

cpe:2.3:a:horilla:horilla:1.3:*:*:*:*:*:*:*

History

29 Sep 2025, 14:05

Type Values Removed Values Added
References () https://github.com/horilla-opensource/horilla/security/advisories/GHSA-99h5-x29f-727w - () https://github.com/horilla-opensource/horilla/security/advisories/GHSA-99h5-x29f-727w - Exploit, Vendor Advisory
First Time Horilla
Horilla horilla
CPE cpe:2.3:a:horilla:horilla:1.3:*:*:*:*:*:*:*

24 Sep 2025, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-09-24 18:15

Updated : 2025-09-29 14:05


NVD link : CVE-2025-48869

Mitre link : CVE-2025-48869

CVE.ORG link : CVE-2025-48869


JSON object : View

Products Affected

horilla

  • horilla
CWE
CWE-284

Improper Access Control