{"id":"CVE-2026-71483","title":"Horilla is an HR and CRM software","summary":"Horilla is an HR and CRM software. Prior to 1.6.0, the search parameter at /employee/employee-filter-view is reflected by jQuery .html() in employee/templates/employee_nav.html without HTML neutralization. An external attacker can craft …","severity":"high","cvss":8.5,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N","cwe":["CWE-79"],"vendor":"horilla","product":"horilla-hr","affected":["horilla-hr < 1.6.0"],"published":"2026-09-25","updated":"2026-09-25","sourceUpdated":"2026-09-25T22:18:20.173","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-71483","references":[{"url":"https://github.com/horilla/horilla-hr/commit/39ed01306341a1f6b7702df2825ab5431b5401a9","label":"security-advisories@github.com"},{"url":"https://github.com/horilla/horilla-hr/security/advisories/GHSA-rw86-x8hq-xgwh","label":"security-advisories@github.com"}],"tags":["nvd","cve.org"],"cvssSource":"cna","ingestedAt":"2026-09-25T22:20:31.563Z","slug":"CVE-2026-71483","body":"## Overview\n\nHorilla is an HR and CRM software. Prior to 1.6.0, the search parameter at /employee/employee-filter-view is reflected by jQuery .html() in employee/templates/employee_nav.html without HTML neutralization. An external attacker can craft and deliver a link that causes JavaScript to execute when an authenticated employee or administrator reaches the employee filter, allowing access to browser-visible session data and actions with the victim's application privileges. This issue is fixed in version 1.6.0.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":47,"depthScoreParts":{"impact":46.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}