CVE-2026-24034 | horilla-opensource horilla up to 1.4.x Profile Photo Update unrestricted upload (GHSA-mvwg-7c8w-qw2p)
A vulnerability was found in horilla-opensource horilla up to 1.4.x. It has been declared as critical. Impacted is an unknown function of the component Profile Photo Update Handler. Executing a manipulation can lead to unrestricted upload.
This vulnerability is tracked as CVE-2026-24034. The attack can be launched remotely. No exploit exists.
It is recommended to upgrade the affected component.