CVE-2026-108100
HortusFox before 6.2 SQL Injection via /api/locations/list include_info Parameter
CVSS Score
6.5
EPSS Score
0.0%
EPSS Percentile
0th
HortusFox (hortusfox-web) before 6.2 contains an SQL injection vulnerability that allows API token holders to inject SQL by supplying crafted include_info values to the /api/locations/list endpoint. Attackers can place subqueries in include_info, which PlantsModel::getSpecificInfo() concatenates into the column list, to read any database table including user password hashes.
| CWE | CWE-89 |
| Vendor | danielbrendel |
| Product | hortusfox-web |
| Published | Oct 9, 2026 |
Stay Ahead of the Next One
Get instant alerts for danielbrendel hortusfox-web
Be the first to know when new medium vulnerabilities affecting danielbrendel hortusfox-web are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None
Affected Versions
danielbrendel / hortusfox-web
0 < 6.2
References
github.com: https://github.com/danielbrendel/hortusfox-web/commit/c0c0f4057dd8376b63c34028de36c8c6b6288fee github.com: https://github.com/danielbrendel/hortusfox-web github.com: https://github.com/danielbrendel/hortusfox-web/security/advisories/GHSA-4w8p-x2jj-42w7 github.com: https://github.com/danielbrendel/hortusfox-web/blob/v6.1/app/models/PlantsModel.php#L1026-L1033 github.com: https://github.com/danielbrendel/hortusfox-web/blob/v6.1/app/controller/api.php#L642-L650 vulncheck.com: https://www.vulncheck.com/advisories/hortusfox-before-6.2-sql-injection-via-api-locations-list-include-info-parameter
Credits
hackchang ๐ leediay153 from Viettel Post