PT-2026-99138 · Horilla · Horilla
CVE-2026-86066
·
Published
2026-09-25
·
Updated
2026-09-28
CVSS v4.0
5.9
Medium
| Vector | AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Horilla versions prior to 2.0.0
Description
An issue exists where the endpoint '/attendance/approve-validate-attendance-request/' modifies
attendance validated, is validate request approved, approved by, and pending-request states via an HTTP GET request before calling the attendance.save() function. Because Django does not require Cross-Site Request Forgery (CSRF) validation for GET requests, an unauthenticated attacker can trick a logged-in manager with attendance.change attendance permissions into making a top-level request. This allows the attacker to silently approve attendance using the manager's privileges and attribute the action to the victim in the audit trail.Recommendations
Update to version 2.0.0.
Exploit
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Horilla