โ† All reports

The Horilla HRMS system has vulnerabilities that allow authenticated users to access other employees' documents and view attachments from other tickets.

CybersecurityTechnologyConflictApr 21, 2026score 0.172 posts ยท 0 replies across 1 instances
Two vulnerabilities were reported in the open-source HRMS system Horilla, affecting its document viewer and helpdesk attachment viewer. These vulnerabilities allow authenticated users to access other employees' documents and view attachments from other tickets, posing a security risk.

Claims

The Horilla HRMS system has vulnerabilities that allow authenticated users to access other employees' documents and view attachments from other tickets.
Parent: CybersecurityEntity: Horilla HRMSImpact: negativeDate: Apr 21, 2026Target: The Horilla HRMS system's security measures

Source posts

@[email protected]
๐Ÿšจ EUVD-2026-24231 ๐Ÿ“Š Score: 7.1/10 (CVSS v3.1) ๐Ÿ“ฆ Product: horilla ๐Ÿข Vendor: horilla-opensource ๐Ÿ“… Updated: 2026-04-21 ๐Ÿ“ Horilla is a free and open source Human Resource Management System (HRMS). In 1.5.0, an insecure direct object reference in the employee document viewer allows any authenticated user to access other employeesโ€™ uploaded documents by changing the do... ๐Ÿ”— https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-24231 #cybersecurity #infosec #euvd #cve #vulnerability
0 boosts ยท 0 favs ยท 0 replies ยท Apr 21, 2026
#cybersecurity#infosec#euvd#cve#vulnerability
@[email protected]
๐Ÿšจ EUVD-2026-24235 ๐Ÿ“Š Score: 7.1/10 (CVSS v3.1) ๐Ÿ“ฆ Product: horilla ๐Ÿข Vendor: horilla-opensource ๐Ÿ“… Updated: 2026-04-21 ๐Ÿ“ Horilla is a free and open source Human Resource Management System (HRMS). In 1.5.0, a broken access control vulnerability in the helpdesk attachment viewer allows any authenticated user to view attachments from other tickets by changing the attac... ๐Ÿ”— https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-24235 #cybersecurity #infosec #euvd #cve #vulnerability
0 boosts ยท 0 favs ยท 0 replies ยท Apr 21, 2026
#cybersecurity#infosec#euvd#cve#vulnerability
@[email protected]
๐Ÿšจ EUVD-2026-24234 ๐Ÿ“Š Score: 8.6/10 (CVSS v3.1) ๐Ÿ“ฆ Product: horilla ๐Ÿข Vendor: horilla-opensource ๐Ÿ“… Updated: 2026-04-21 ๐Ÿ“ Horilla is a free and open source Human Resource Management System (HRMS). In 1.5.0, an insecure direct object reference in the employee document upload endpoint allows any authenticated user to overwrite or replace or corrupt another employeeโ€™s d... ๐Ÿ”— https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-24234 #cybersecurity #infosec #euvd #cve #vulnerability
0 boosts ยท 0 favs ยท 0 replies ยท Apr 21, 2026
#cybersecurity#infosec#euvd#cve#vulnerability