GHSA-cwp7-9356-rvxxHighCVSS 6.5
HortusFox (hortusfox-web) before 6.2 contains an SQL injection vulnerability that allows API...
🔗 CVE IDs covered (1)
📋 Description
HortusFox (hortusfox-web) before 6.2 contains an SQL injection vulnerability that allows API token holders to inject SQL by supplying crafted include_info values to the /api/locations/list endpoint. Attackers can place subqueries in include_info, which PlantsModel::getSpecificInfo() concatenates into the column list, to read any database table including user password hashes.
🔗 References (8)
- https://github.com/danielbrendel/hortusfox-web/security/advisories/GHSA-4w8p-x2jj-42w7
- https://nvd.nist.gov/vuln/detail/CVE-2026-108100
- https://github.com/danielbrendel/hortusfox-web/commit/c0c0f4057dd8376b63c34028de36c8c6b6288fee
- https://github.com/danielbrendel/hortusfox-web
- https://github.com/danielbrendel/hortusfox-web/blob/v6.1/app/controller/api.php#L642-L650
- https://github.com/danielbrendel/hortusfox-web/blob/v6.1/app/models/PlantsModel.php#L1026-L1033
- https://www.vulncheck.com/advisories/hortusfox-before-6.2-sql-injection-via-api-locations-list-include-info-parameter
- https://github.com/advisories/GHSA-cwp7-9356-rvxx