CVE 4.8 MEDIUM

Horilla: Open Redirect via Unvalidated `next` Parameter in Notification Endpoints_CVE-2026-41513

4.8 / 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N

Description

Horilla is an HR and CRM software. In 1.5.0, the notification endpoints trust the unvalidated next parameter and redirect users to arbitrary external URLs. This allows an attacker to turn trusted application links into phishing or social-engineering redirects.

Basic Information

ID CVE-2026-41513
Source GitHub_M
Published May 12, 2026 at 16:43

Affected Product

Vendor horilla
Product horilla-hr
Version <= 1.5.0
Affected Versions horilla horilla-hr <= 1.5.0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.