CVE-2025-59525: Horilla has Improper Input Sanitization Leading to XSS and Admin Account Takeover
Horilla is a free and open source Human Resource Management System (HRMS). Prior to version 1.4.0, improper sanitization across the application allows XSS via uploaded SVG (and via allowed <embed>), which can be chained to execute JavaScript whenever users view impacted content (e.g., announcements). This can result in admin account takeover. This issue has been patched in version 1.4.0.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-59525?
CVE-2025-59525 has been classified with a high severity level due to the risk of XSS attacks affecting user-generated content.
How do I fix CVE-2025-59525?
To fix CVE-2025-59525, you should upgrade to version 1.4.0 or later of the Horilla HRMS.
What vulnerability type is CVE-2025-59525?
CVE-2025-59525 is classified as a Cross-Site Scripting (XSS) vulnerability.
Which versions of Horilla HRMS are affected by CVE-2025-59525?
CVE-2025-59525 affects all versions of Horilla HRMS prior to version 1.4.0.
What can attackers achieve using CVE-2025-59525?
Attackers can exploit CVE-2025-59525 to execute arbitrary JavaScript in the context of users viewing affected content.