CVE-2025-59832: Horrila Stored XSS Vulnerability via Ticket Comment section
Horilla is a free and open source Human Resource Management System (HRMS). Prior to version 1.4.0, there is a stored XSS vulnerability in the ticket comment editor. A low-privilege authenticated user could run arbitrary JavaScript in an admin’s browser, exfiltrate the admin’s cookies/CSRF token, and hijack their session. This issue has been patched in version 1.4.0.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-59832?
CVE-2025-59832 is classified as a low severity vulnerability due to its requirement for low-privilege authenticated user access.
How do I fix CVE-2025-59832?
To fix CVE-2025-59832, you should upgrade the Horilla Human Resource Management System to version 1.4.0 or later.
What type of vulnerability is CVE-2025-59832?
CVE-2025-59832 is a stored XSS (Cross-Site Scripting) vulnerability.
Who is affected by CVE-2025-59832?
CVE-2025-59832 affects users of the Horilla Human Resource Management System prior to version 1.4.0.
What could an attacker do with CVE-2025-59832?
An attacker could exploit CVE-2025-59832 to run arbitrary JavaScript in an admin's browser and potentially exfiltrate their cookies.