Impact
Horilla Employee Filter View exposes a reflected cross‑site scripting flaw. User input entered as a search parameter at /employee/employee-filter-view is inserted into the page via jQuery .html() without neutralization, permitting an attacker to inject arbitrary JavaScript. When an authenticated user or administrator visits a crafted link, the attacker’s script runs in the victim’s browser context, enabling theft of session cookies and execution of privileged actions on behalf of the authenticated user.
Affected Systems
The vulnerability affects Horilla HR version 1.5.x and earlier. Version 1.6.0 and above include the fix.
Risk and Exploitability
The CVSS score of 8.5 indicates high severity for a reflected XSS that can access application data. No EPSS score is available, so the historical exploitation probability is unknown. The issue is not listed in the CISA KEV catalog. Exploitation requires traffic to the vulnerable endpoint and a user with valid credentials to open the crafted link; thus the attack vector is likely social engineering via a malicious URL.
OpenCVE Enrichment