CVE-2025-48869 HIGH

CVE-2025-48869: Horilla Unauthorized Access to Candidate Resume Files Due to Broken Access Control

Vendor Horilla-Opensource
Product horilla
Weakness CWE-284
Published September 24, 2025
Last update September 24, 2025

CVSS base score

7.5/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality High
Integrity None

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

What the vulnerability does

01Description

Horilla is a free and open source Human Resource Management System (HRMS). Unauthenticated users can access uploaded resume files in Horilla 1.3.0 by directly guessing or predicting file URLs. These files are stored in a publicly accessible directory, allowing attackers to retrieve sensitive candidate information without authentication. At time of publication there is no known patch.

Key dates

02Disclosure timeline

September 24, 2025 CVE published
September 24, 2025 Record updated