<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:hortusfox:hortusfox:*:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3ahortusfoxhortusfox/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Tue, 06 Oct 2026 16:56:30 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3ahortusfoxhortusfox/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Remote Code Execution in HortusFox ThemeModule</title><link>https://feed.craftedsignal.io/briefs/2026-10-cve-2026-104069/</link><pubDate>Tue, 06 Oct 2026 16:56:30 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-cve-2026-104069/</guid><description>HortusFox versions prior to 6.2 are vulnerable to remote code execution via an insufficient validation flaw in the theme import process allowing arbitrary file uploads to the web root.</description><content:encoded><![CDATA[<p>HortusFox versions prior to 6.2 are affected by a remote code execution vulnerability located within the ThemeModule::startImport() function. The vulnerability stems from an insecure file handling implementation where uploaded ZIP archives are extracted directly into the application's public web root. Critically, the system performs no validation on the file names, extensions, or content of the extracted files prior to placement in an executable directory. An authenticated administrator can leverage this by uploading a specially crafted theme archive containing both a malicious PHP script and an .htaccess file, which bypasses typical execution restrictions. By subsequently requesting the uploaded file via the themes directory, an attacker can execute arbitrary OS commands under the privileges of the web-server user.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>Authenticated attacker logs into the HortusFox administrative interface.</li>
<li>Attacker prepares a ZIP archive containing a PHP web shell and a custom .htaccess configuration file.</li>
<li>Attacker navigates to the theme import feature and uploads the crafted ZIP archive.</li>
<li>The application processes the upload through the vulnerable ThemeModule::startImport() function.</li>
<li>The application extracts the contents of the ZIP archive directly into the public web root directory without validation.</li>
<li>The .htaccess file is applied by the web server, enabling PHP execution for the attacker's script if previously restricted.</li>
<li>Attacker requests the path to the uploaded PHP shell via a standard HTTP GET request.</li>
<li>Web server executes the PHP script, providing the attacker with remote command execution capabilities.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of this vulnerability allows an authenticated administrator to achieve full remote code execution on the underlying server. This results in complete compromise of the web application, potential lateral movement within the network, and access to sensitive data stored on or accessible to the web server process. The scope is limited to HortusFox instances running version 6.1 or earlier.</p>
<h2 id="recommendation">Recommendation</h2>
<ol>
<li>Upgrade all HortusFox installations to version 6.2 or later immediately to patch the vulnerable ThemeModule::startImport() function.</li>
<li>Implement strict file system permissions on the public web root to prevent the web server process from writing new executable files in directories where they are not required.</li>
<li>Deploy file integrity monitoring on the /themes directory to alert on the creation of unexpected .php or .htaccess files.</li>
<li>Enable and monitor web server access logs for requests to non-standard or unexpected files within the /themes directory structure.</li>
</ol>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category></item></channel></rss>