CVE-2025-59525 - Horilla has Improper Input Sanitization Leading to XSS and Admin Account Takeover
CVE ID : CVE-2025-59525
Published : Sept. 24, 2025, 7:15 p.m. | 2 hours, 23 minutes ago
Description : Horilla is a free and open source Human Resource Management System (HRMS). Prior to version 1.4.0, improper sanitization across the application allows XSS via uploaded SVG (and via allowed
Published : Sept. 24, 2025, 7:15 p.m. | 2 hours, 23 minutes ago
Description : Horilla is a free and open source Human Resource Management System (HRMS). Prior to version 1.4.0, improper sanitization across the application allows XSS via uploaded SVG (and via allowed