EudorIACyber Intelligence
Monitoraggio operativo Newsletter IT EN
← Torna all intelligence correlata
Vulnerabilità

CVE-2026-71483

Scheda descrittiva ricevuta da OpenCTI e minimizzata per la consultazione nel portale Intel.

Condivisione
PUBLIC-OSINT
Confidenza
100
Fonte
The CVE Program
Aggiornata
26/09/2026 05:01

Descrizione

Horilla is an HR and CRM software. Prior to 1.6.0, the search parameter at /employee/employee-filter-view is reflected by jQuery .html() in employee/templates/employee_nav.html without HTML neutralization. An external attacker can craft and deliver a link that causes JavaScript to execute when an authenticated employee or administrator reaches the employee filter, allowing access to browser-visible session data and actions with the victim's application privileges. This issue is fixed in version 1.6.0.

Identificativo STIXvulnerability--18d6d4cb-2d44-57c6-b603-8950eaff0884
Prima osservazione-
Ultima osservazione-
Relazioni censite6

Alias e classificazioni

CWE-79Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Dettagli tecnici minimizzati

Nessun dato grezzo
cisa kev
False
Correlazione EudorIA

Catalogo Intel

La vulnerabilità è presente anche nel catalogo editoriale EudorIA.

Apri analisi EudorIA

La presenza in OpenCTI descrive una correlazione di intelligence e non costituisce, da sola, prova di compromissione, attribuzione legale o indicazione operativa applicabile senza verifica del contesto.