PT-2026-99135 · Horilla · Horilla
CVE-2026-63431
·
Published
2026-09-25
·
Updated
2026-09-30
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Horilla versions 1.5.0-85 and earlier
Description
An authentication bypass exists in the payroll module where the system fails to consistently authorize access before loading records. An authenticated employee can manipulate identifiers to access sensitive data belonging to other employees, including salary structures, allowance and deduction amounts, personal loan disbursements, and repayment schedules. This occurs within the
payroll/views/component views.py file specifically in the allowances deductions tab, view single allowance(), and view single deduction() functions when processing the emp id, allowance id, or deduction id variables.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Horilla