Remote Code Execution in HortusFox by Daniel Brendel
CVE-2026-104069
8.6HIGH
What is CVE-2026-104069?
HortusFox before version 6.2 has a significant vulnerability in the ThemeModule::startImport() function. This flaw allows an authenticated administrator to upload a specially crafted ZIP archive that contains malicious PHP code and an .htaccess file. The lack of validation on the file names, extensions, and content when extracting the archive directly into the public web root can lead to unauthorized execution of arbitrary OS commands as the web server user. This vulnerability highlights the critical need for rigorous file validation protocols in any application dealing with file uploads.
Affected Version(s)
hortusfox-web 0 < 6.2
