VYPR
High severity7.2NVD Advisory· Published Sep 24, 2025· Updated Jun 17, 2026

CVE-2025-48868

CVE-2025-48868

Description

Horilla is a free and open source Human Resource Management System (HRMS). An authenticated Remote Code Execution (RCE) vulnerability exists in Horilla 1.3.0 due to the unsafe use of Python’s eval() function on a user-controlled query parameter in the project_bulk_archive view. This allows privileged users (e.g., administrators) to execute arbitrary system commands on the server. While having Django’s DEBUG=True makes exploitation visibly easier by returning command output in the HTTP response, this is not required. The vulnerability can still be exploited in DEBUG=False mode by using blind payloads such as a reverse shell, leading to full remote code execution. This issue has been patched in version 1.3.1.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • cpe:2.3:a:horilla:horilla:1.3:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:horilla:horilla:1.3:*:*:*:*:*:*:*
    • (no CPE)range: <1.3.1
    • (no CPE)range: = 1.3.0

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.