GHSA-cwp7-9356-rvxxHighCVSS 6.5

HortusFox (hortusfox-web) before 6.2 contains an SQL injection vulnerability that allows API...

Published
October 9, 2026
Last Modified
October 9, 2026

🔗 CVE IDs covered (1)

📋 Description

HortusFox (hortusfox-web) before 6.2 contains an SQL injection vulnerability that allows API token holders to inject SQL by supplying crafted include_info values to the /api/locations/list endpoint. Attackers can place subqueries in include_info, which PlantsModel::getSpecificInfo() concatenates into the column list, to read any database table including user password hashes.

🔗 References (8)