CVE WATCH / VULNERABILITY DETAIL

CVE-2026-96795

HIGHCVSS 8.8NVD feed

Published 25 September 2026 · tracked since 26 September 2026

Description

Horilla is an HR and CRM software. Prior to 2.0.0, HorillaListView.export_data in horilla_views/generic/cbv/views.py accepts an authenticated user's columns POST parameter, takes field_tuple[1], interpolates it into dynamic_fn_str as Python source, and passes the generated function definition to exe

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

CVE-2026-96795 — Vulnerability Details | Logic Encoder
CVE WATCH / VULNERABILITY DETAIL

CVE-2026-96795

HIGHCVSS 8.8NVD feed

Published 25 September 2026 · tracked since 26 September 2026

Description

Horilla is an HR and CRM software. Prior to 2.0.0, HorillaListView.export_data in horilla_views/generic/cbv/views.py accepts an authenticated user's columns POST parameter, takes field_tuple[1], interpolates it into dynamic_fn_str as Python source, and passes the generated function definition to exe

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

[an error occurred while processing this directive]