CNNVD-202601-3893 Information

CNNVD ID

CNNVD-202601-3893

CVE-2026-24039

  • CNNVD Published: 2026-01-22

Description (Chinese)

Horilla是Horilla公司的一款免费的开源人力资源软件。 Horilla 1.4.0版本存在访问控制错误漏洞,该漏洞源于服务器端对审批端点的授权检查不足,可能导致低权限员工自我批准其上传的文档。

Description (English)

Horilla is a free open-source human resources software for Horilla. Version Horilla 1.4.0 contains a bug in access control, which stems from inadequate server-end authorization checks of approval endpoints, which may lead to low-authorized staff self-approval of their uploading documents.

Hazard Level

High

Vulnerability Type

访问控制错误

Affected Vendor

Horilla

Published

2026-01-22

Last Modified

2026-02-24

References

https://github.com/horilla-opensource/horilla/releases/tag/1.5.0 https://github.com/horilla-opensource/horilla/security/advisories/GHSA-99mq-mhwv-w9qx

Patch

https://github.com/horilla-opensource/horilla/releases

Share on: