High severity7.5NVD Advisory· Published Sep 24, 2025· Updated Jun 17, 2026
CVE-2025-48869
CVE-2025-48869
Description
Horilla is a free and open source Human Resource Management System (HRMS). Unauthenticated users can access uploaded resume files in Horilla 1.3.0 by directly guessing or predicting file URLs. These files are stored in a publicly accessible directory, allowing attackers to retrieve sensitive candidate information without authentication. At time of publication there is no known patch.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:horilla:horilla:1.3:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:horilla:horilla:1.3:*:*:*:*:*:*:*
- (no CPE)range: <1.3.0
- (no CPE)range: = 1.3.0
Patches
Vulnerability mechanics
References
1- github.com/horilla-opensource/horilla/security/advisories/GHSA-99h5-x29f-727wnvdExploitVendor Advisory
News mentions
0No linked articles in our index yet.