CVE-2026-41513
Vulnerability Description
Horilla is an HR and CRM software. In 1.5.0, the notification endpoints trust the unvalidated next parameter and redirect users to arbitrary external URLs. This allows an attacker to turn trusted application links into phishing or social-engineering redirects.
Vulnerability Details
Published Date
Last Modified
CWE ID
CWE-601
Source
NVD
Vendor
horilla
Product
horilla-hr
Discussion (0)
Add Comment
No comments yet. Be the first!