CVE-2024-12138: horilla create_skills deserialization
A vulnerability classified as critical was found in horilla up to 1.2.1. This vulnerability affects the function requestnew/getemployeeshift/createreimbursement/keyresultcurrentvalueupdate/createmeetings/createskills. The manipulation leads to deserialization. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-12138?
CVE-2024-12138 is classified as a critical vulnerability.
How does CVE-2024-12138 affect the software?
CVE-2024-12138 affects multiple functions including request_new, get_employee_shift, and others, leading to deserialization issues.
Which versions of horilla are affected by CVE-2024-12138?
CVE-2024-12138 affects horilla versions up to 1.2.1.
What are the potential impacts of exploiting CVE-2024-12138?
Exploiting CVE-2024-12138 may allow unauthorized access or manipulation of sensitive data within the system.
How can I remediate CVE-2024-12138?
To remediate CVE-2024-12138, you should upgrade horilla to a version later than 1.2.1.