SQL Injection Vulnerability in HortusFox Web Application
CVE-2026-108100

7.1HIGH

Key Information:

Vendor
CVE Published:
9 October 2026

What is CVE-2026-108100?

An SQL injection vulnerability exists in the HortusFox web application prior to version 6.2, specifically affecting the /api/locations/list endpoint. This issue arises when API token holders supply crafted values to the include_info parameter, allowing attackers to inject subqueries through the PlantsModel::getSpecificInfo() function. This manipulation can lead to unauthorized access to database tables, including sensitive information such as user password hashes, posing a significant risk to data security.

Affected Version(s)

hortusfox-web 0 < 6.2

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

hackchang
leediay153 from Viettel Post
.