Unrestricted File Upload Vulnerability in HortusFox Web Application
CVE-2026-108101

7.7HIGH

Key Information:

Vendor
CVE Published:
9 October 2026

What is CVE-2026-108101?

HortusFox Version 6.3 contains a vulnerability in the PlantAttachmentModel that permits authenticated users to upload files without proper validation. This weakness allows the upload of potentially harmful HTML, SVG, or PHP files to the public/attachments/ directory. Attackers can exploit this flaw to carry out stored cross-site scripting attacks or execute arbitrary code, especially when .htaccess file restrictions are not enforced, leading to severe security risks.

Affected Version(s)

hortusfox-web 0 <= 6.3

References

CVSS V4

Score:
7.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

leediay153 from Viettel Post
hackchang
.