Unrestricted File Upload Vulnerability in HortusFox Web Application
CVE-2026-108101
7.7HIGH
What is CVE-2026-108101?
HortusFox Version 6.3 contains a vulnerability in the PlantAttachmentModel that permits authenticated users to upload files without proper validation. This weakness allows the upload of potentially harmful HTML, SVG, or PHP files to the public/attachments/ directory. Attackers can exploit this flaw to carry out stored cross-site scripting attacks or execute arbitrary code, especially when .htaccess file restrictions are not enforced, leading to severe security risks.
Affected Version(s)
hortusfox-web 0 <= 6.3
