Unrestricted File Upload in HortusFox hortusfox-web
HortusFox hortusfox-web through version 6.3 is vulnerable to unrestricted file uploads in the PlantAttachmentModel, allowing authenticated attackers to execute remote code or perform stored cross-site scripting.
CVE search metadata
CVE search record: CVE-2026-108101. Severity: high. CVSS: 7.5. KEV: no. Product: hortusfox-web (<= 6.3). Brief: Unrestricted File Upload in HortusFox hortusfox-web. Brief link: https://feed.craftedsignal.io/briefs/2026-10-hortusfox-upload/
HortusFox (hortusfox-web) versions through 6.3 contain an unrestricted file upload vulnerability in the PlantAttachmentModel. The application fails to properly validate the file extensions of user-supplied attachments when using the /plants/attachments/add endpoint. Authenticated users can upload arbitrary file types, which are subsequently stored in the public/attachments/ directory. If the underlying server environment lacks strict .htaccess enforcement or other execution restrictions, an attacker can upload and execute malicious PHP scripts to gain remote code execution. Additionally, the ability to upload HTML or SVG files permits stored cross-site scripting (XSS) attacks, which could be used to compromise the sessions of other authenticated users or administrators interacting with the application. Defenders should prioritize restricting upload directories and enforcing strict file extension allow-lists on the server side.
Attack Chain
- Attacker authenticates to the HortusFox web application with valid user credentials.
- Attacker navigates to the endpoint /plants/attachments/add for document management.
- Attacker intercepts the file upload request to modify the file content and extension.
- Attacker uploads a malicious PHP script or an HTML/SVG file containing XSS payloads.
- The application saves the file to the public/attachments/ directory without validating the extension.
- Attacker requests the stored file via the browser or directly accesses the file URL.
- The server executes the uploaded PHP script or renders the HTML/SVG file in the context of the user session.
- Attacker gains remote code execution on the web server or successfully executes unauthorized scripts in the browser.
Impact
Successful exploitation allows authenticated attackers to gain remote code execution (RCE) on the server, potentially leading to a full system compromise. Alternatively, attackers can perform stored XSS to hijack administrator sessions or perform actions on behalf of other users. This vulnerability impacts all installations of hortusfox-web versions 6.3 and earlier.
Recommendation
- Upgrade hortusfox-web to a version beyond 6.3 immediately to address the insecure validation in PlantAttachmentModel.
- Implement server-side execution restrictions on the public/attachments/ directory, ensuring it is configured as a non-executable area (e.g., via web server configuration to disable PHP execution in this path).
- Deploy a web application firewall (WAF) rule to block POST requests to /plants/attachments/add that contain suspicious file extensions or MIME types not associated with legitimate plant attachments.
Immediate actions
Upgrade hortusfox-web to version 6.4 or later
Mitigations
Configure web server to prevent script execution in public/attachments/
CVE-2026-108101
Detection coverage 1
Detect CVE-2026-108101 Exploitation - Suspicious File Uploads to HortusFox
highDetects exploitation of CVE-2026-108101 by monitoring for unauthorized file uploads targeting the HortusFox attachment endpoint.
Detection queries are available on the platform. Get full rules →