CVE-2026-24010CWE-474CWE-74

Horilla has HTML Injection Issue that, with Phishing, Leads to Account Takeover

High · published January 22, 2026

CVSS v3.0
8.8
EPSS
0%
Percentile
35.9
In the wild
Unconfirmed
What it is

🚨 A single malicious HTML file can turn a smooth user experience into a phishing nightmare! Users of Horilla (prior to version 1.5.0) are at risk as attackers can easily impersonate a login page and steal credentials. 🔥 Think of it like a crafty barista slipping a fake menu into a café — customers are blissfully unaware that their orders will be taken by a fraudster. By masquerading as something familiar, the attacker can capture sensitive information without raising any alarms. If exploited, an attacker could create a deceptive login screen that prompts users to re-authenticate, leading to stolen credentials and account takeovers. This could result in unauthorized access to sensitive HR data and catastrophic consequences for both users and the organization.

Put simply

Think of it like a crafty barista slipping a fake menu into a café — customers are blissfully unaware that their orders will be taken by a fraudster. By masquerading as something familiar, the attacker can capture sensitive information without raising any alarms. This vulnerability allows authenticated users to upload malicious HTML files disguised as profile pictures, which then serve as phishing pages. When victims visit the URL of the uploaded file, their credentials are captured and sent to the attacker's server.

What to do

If exploited, an attacker could create a deceptive login screen that prompts users to re-authenticate, leading to stolen credentials and account takeovers. This could result in unauthorized access to sensitive HR data and catastrophic consequences for both users and the organization. Update Horilla to version 1.5.0 or later immediately to patch this issue. Additionally, consider implementing file upload restrictions and user education on identifying phishing attempts to bolster security. 🛡️ You've got this! Act quickly to secure your system, and soon you’ll be back to enjoying a safe and sound HR experience! 💪✨

The record
Technical detail
CVSS v3.0
8.8 · HIGH
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS v4.0
Not supplied
EPSS
0.00428 · 35.9th percentile
Weaknesses
CWE-474 · Use of Function with Inconsistent Implementations; CWE-74 · Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
Published
2026-01-22T02:37Z
EPSS history
Timeline
  • 22 JAN 02:37Z
    Horilla has HTML Injection Issue that, with Phishing, Leads to Account Takeover
    cvelistv5