๐Ÿ” CVE Alert

CVE-2026-108100

MEDIUM 6.5

HortusFox before 6.2 SQL Injection via /api/locations/list include_info Parameter

CVSS Score
6.5
EPSS Score
0.0%
EPSS Percentile
0th

HortusFox (hortusfox-web) before 6.2 contains an SQL injection vulnerability that allows API token holders to inject SQL by supplying crafted include_info values to the /api/locations/list endpoint. Attackers can place subqueries in include_info, which PlantsModel::getSpecificInfo() concatenates into the column list, to read any database table including user password hashes.

CWE CWE-89
Vendor danielbrendel
Product hortusfox-web
Published Oct 9, 2026
Stay Ahead of the Next One

Get instant alerts for danielbrendel hortusfox-web

Be the first to know when new medium vulnerabilities affecting danielbrendel hortusfox-web are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None

Affected Versions

danielbrendel / hortusfox-web
0 < 6.2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/danielbrendel/hortusfox-web/commit/c0c0f4057dd8376b63c34028de36c8c6b6288fee github.com: https://github.com/danielbrendel/hortusfox-web github.com: https://github.com/danielbrendel/hortusfox-web/security/advisories/GHSA-4w8p-x2jj-42w7 github.com: https://github.com/danielbrendel/hortusfox-web/blob/v6.1/app/models/PlantsModel.php#L1026-L1033 github.com: https://github.com/danielbrendel/hortusfox-web/blob/v6.1/app/controller/api.php#L642-L650 vulncheck.com: https://www.vulncheck.com/advisories/hortusfox-before-6.2-sql-injection-via-api-locations-list-include-info-parameter

Credits

hackchang ๐Ÿ” leediay153 from Viettel Post