CVE-2026-86066
Scheda descrittiva ricevuta da OpenCTI e minimizzata per la consultazione nel portale Intel.
- Condivisione
- PUBLIC-OSINT
- Confidenza
- 100
- Fonte
- The CVE Program
- Aggiornata
- 26/09/2026 04:09
Descrizione
Horilla is an HR and CRM software. Prior to 2.0.0, approve_validate_attendance_request at /attendance/approve-validate-attendance-request/ changes attendance_validated, is_validate_request_approved, approved_by, and related pending-request state through an HTTP GET before calling attendance.save(), so Django does not require CSRF validation for the action. An unauthenticated attacker can cause a logged-in manager with attendance.change_attendance to make a top-level request that carries the manager's SameSite=Lax session cookie, silently approving attendance with the victim's privileges and attributing the approval to the victim in the audit trail. This issue is fixed in version 2.0.0.
Alias e classificazioni
Dettagli tecnici minimizzati
Nessun dato grezzo- cisa kev
- False
Riferimenti pubblici
- https://github.com/horilla/horilla-hr/releases/tag/2.0.0
https://github.com/horilla/horilla-hr/releases/tag/2.0.0 - https://github.com/horilla/horilla-hr/security/advisories/GHSA-65vj-5p5g-pv5m
https://github.com/horilla/horilla-hr/security/advisories/GHSA-65vj-5p5g-pv5m - https://github.com/horilla/horilla-hr/commit/87a23ecaf2944c15dc5c131f813d2b83fd56eaa0
https://github.com/horilla/horilla-hr/commit/87a23ecaf2944c15dc5c131f813d2b83fd56eaa0
Catalogo Intel
La vulnerabilità è presente anche nel catalogo editoriale EudorIA.
Apri analisi EudorIALa presenza in OpenCTI descrive una correlazione di intelligence e non costituisce, da sola, prova di compromissione, attribuzione legale o indicazione operativa applicabile senza verifica del contesto.