CVE-2025-48869

Source
https://cve.org/CVERecord?id=CVE-2025-48869
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-48869.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-48869
Aliases
  • GHSA-99h5-x29f-727w
Published
2025-09-24T17:17:40Z
Modified
2026-08-27T03:57:04Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
Horilla Unauthorized Access to Candidate Resume Files Due to Broken Access Control
Details

Horilla is a free and open source Human Resource Management System (HRMS). Unauthenticated users can access uploaded resume files in Horilla 1.3.0 by directly guessing or predicting file URLs. These files are stored in a publicly accessible directory, allowing attackers to retrieve sensitive candidate information without authentication. At time of publication there is no known patch.

Database specific
{
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-284"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/48xxx/CVE-2025-48869.json",
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "introduced": "= 1.3.0"
                },
                {
                    "last_affected": "= 1.3.0"
                }
            ],
            "source": "AFFECTED_FIELD"
        }
    ]
}
References

Affected packages

Git / github.com/horilla/horilla-hr

Affected ranges

Type
GIT
Repo
https://github.com/horilla/horilla-hr
Events
Database specific
Show details
{
    "cpe": "cpe:2.3:a:horilla:horilla:1.3:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "1.3"
        },
        {
            "last_affected": "1.3"
        }
    ],
    "source": "CPE_STRING"
}

Affected versions

1.*
1.3

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-48869.json"