Loading vulnerability details…
CVSS v3.1
N/A
CVSS v4.0
4.8
EPSS
0.27%
Published
May 12, 2026
Modified
May 13, 2026
Public PoC / Exploit (1)
All weaponized →Links to public security research (Exploit-DB, Nuclei, Trickest, GitHub) for defensive use only.
Description
Horilla is an HR and CRM software. In 1.5.0, the notification endpoints trust the unvalidated next parameter and redirect users to arbitrary external URLs. This allows an attacker to turn trusted application links into phishing or social-engineering redirects.
Weaknesses (CWE)
References (3)