Description


HortusFox (hortusfox-web) before 6.2 contains an SQL injection vulnerability that allows API token holders to inject SQL by supplying crafted include_info values to the /api/locations/list endpoint. Attackers can place subqueries in include_info, which PlantsModel::getSpecificInfo() concatenates into the column list, to read any database table including user password hashes.

Related CPE's


Could not find any relations

Weaknesses



CWE-89

CVSS impact metrics


CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

6.5 · Medium

Information


Source identifier

[email protected]

Vulnerability status

Deferred

Published

2026-10-09T15:17:10.443Z

1 hour ago

Last modified

2026-10-09T15:17:10.583Z

1 hour ago