PT-2026-99136 · Horilla · Horilla
CVE-2026-63432
·
Published
2026-09-25
·
Updated
2026-09-28
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Horilla versions 1.0.0 through 1.5.9
Horilla version 2.0.0 (affected versions not specified)
Description
The
get mail preview handlers in recruitment/views/actions.py and employee/not in out dashboard.py render a user-controlled body at the endpoints '/recruitment/get-mail-preview/' and '/employee/get-employee-mail-preview' using the full request object in the Django template context. An authenticated user with a valid CSRF token can perform template attribute traversal to access request.user.password, request.META, and related-user attributes. This leads to the disclosure of password hashes, personal data, and server request metadata, which could facilitate offline password cracking or account compromise. Django template restrictions prevent arbitrary code execution.Recommendations
Update Horilla to version 1.6.0 or later.
Update Horilla to a version newer than 2.0.0.
Exploit
Fix
Code Injection
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Horilla