CVE-2026-24036 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

Horilla is a free and open source Human Resource Management System (HRMS). Versions 1.4.0 and above expose unpublished job postings through the /recruitment/rec…
Medium CVSS: 5.3

CVE-2026-24036

Horilla is a free and open source Human Resource Management System (HRMS). Versions 1.4.0 and above expose unpublished job postings through the /recruitment/recruitment-details// endpoint without authentication. The response includes draft job titles, descriptions and application link allowing unauthenticated users to view unpublished roles and access the application workflow for unpublished jobs. Unauthorized access to unpublished job posts can leak sensitive internal hiring information and cause confusion among candidates. This issue has been fixed in version 1.5.0.
Vendor
Horilla
Product
Horilla
CWE
CWE-284
Yayın Tarihi
2026-01-22 04:15:59
Güncelleme
2026-01-29 18:58:16
Source Identifier
security-advisories@github.com
KEV Date Added
-

Kategoriler

Referanslar