An authenticated Horilla user can turn the list-view export feature into command execution in the application's server environment. This could allow access to HR and CRM data available to the application process, modification of application state, or service disruption.
When the shipped Docker image is used, the advisory states that the container process runs as root by default, increasing the potential impact within the container. Impact beyond the container depends on deployment settings, mounted volumes, secrets, and container permissions, and is not established by the supplied evidence. The existence of the vulnerability alone does not establish that data was exposed or that a compromise occurred.