Metrics
Affected Vendors & Products
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Thu, 25 Sep 2025 08:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Horilla
Horilla horilla |
|
Vendors & Products |
Horilla
Horilla horilla |
Wed, 24 Sep 2025 18:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Wed, 24 Sep 2025 17:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Horilla is a free and open source Human Resource Management System (HRMS). Unauthenticated users can access uploaded resume files in Horilla 1.3.0 by directly guessing or predicting file URLs. These files are stored in a publicly accessible directory, allowing attackers to retrieve sensitive candidate information without authentication. At time of publication there is no known patch. | |
Title | Horilla Unauthorized Access to Candidate Resume Files Due to Broken Access Control | |
Weaknesses | CWE-284 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-09-24T17:26:56.854Z
Reserved: 2025-05-27T20:14:34.295Z
Link: CVE-2025-48869

Updated: 2025-09-24T17:26:26.708Z

Status : Received
Published: 2025-09-24T18:15:37.677
Modified: 2025-09-24T18:15:37.677
Link: CVE-2025-48869

No data.

Updated: 2025-09-25T08:21:03Z