CVE-2026-24010
Severity CVSS v4.0:
Pending analysis
Type:
CWE-74
Injection
Publication date:
22/01/2026
Last modified:
29/01/2026
Description
Horilla is a free and open source Human Resource Management System (HRMS). A critical File Upload vulnerability in versions prior to 1.5.0, with Social Engineering, allows authenticated users to deploy phishing attacks. By uploading a malicious HTML file disguised as a profile picture, an attacker can create a convincing login page replica that steals user credentials. When a victim visits the uploaded file URL, they see an authentic-looking "Session Expired" message prompting them to re-authenticate. All entered credentials are captured and sent to the attacker's server, enabling Account Takeover. Version 1.5.0 patches the issue.
Impact
Base Score 3.x
8.00
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:horilla:horilla:*:*:*:*:*:*:*:* | 1.5.0 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



