{"id":"CVE-2026-71483","published":"2026-09-25T22:18:20.173","lastModified":"2026-09-29T18:17:16.577","description":"Horilla is an HR and CRM software. Prior to 1.6.0, the search parameter at /employee/employee-filter-view is reflected by jQuery .html() in employee/templates/employee_nav.html without HTML neutralization. An external attacker can craft and deliver a link that causes JavaScript to execute when an authenticated employee or administrator reaches the employee filter, allowing access to browser-visible session data and actions with the victim's application privileges. This issue is fixed in version 1.6.0.","cvssScore":null,"cvssSeverity":null,"cvssVector":null,"cwes":["CWE-79"],"vendors":[],"products":[],"references":[{"url":"https://github.com/horilla/horilla-hr/commit/39ed01306341a1f6b7702df2825ab5431b5401a9","tags":[]},{"url":"https://github.com/horilla/horilla-hr/security/advisories/GHSA-rw86-x8hq-xgwh","tags":[]},{"url":"https://github.com/horilla/horilla-hr/security/advisories/GHSA-rw86-x8hq-xgwh","tags":[]}],"exploitRefs":[{"url":"https://github.com/horilla/horilla-hr/commit/39ed01306341a1f6b7702df2825ab5431b5401a9","tags":[]},{"url":"https://github.com/horilla/horilla-hr/security/advisories/GHSA-rw86-x8hq-xgwh","tags":[]},{"url":"https://github.com/horilla/horilla-hr/security/advisories/GHSA-rw86-x8hq-xgwh","tags":[]}],"hasPoc":true,"ai":null}