CVE-2026-108100
MEDIUM
NVD
CVSS Score
6.5
Severity
MEDIUM
Published
Oct 09, 2026
Vendor
unknown
Description
HortusFox (hortusfox-web) before 6.2 contains an SQL injection vulnerability that allows API token holders to inject SQL by supplying crafted include_info values to the /api/locations/list endpoint. Attackers can place subqueries in include_info, which PlantsModel::getSpecificInfo() concatenates into the column list, to read any database table including user password hashes.
References
- https://github.com/danielbrendel/hortusfox-web
- https://github.com/danielbrendel/hortusfox-web/blob/v6.1/app/controller/api.php#L642-L650
- https://github.com/danielbrendel/hortusfox-web/blob/v6.1/app/models/PlantsModel.php#L1026-L1033
- https://github.com/danielbrendel/hortusfox-web/commit/c0c0f4057dd8376b63c34028de36c8c6b6288fee
- https://github.com/danielbrendel/hortusfox-web/security/advisories/GHSA-4w8p-x2jj-42w7