{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/hortusfox--6.2/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:hortusfox:hortusfox:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.2,"id":"CVE-2026-104069"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["HortusFox (\u003c 6.2)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["HortusFox"],"content_html":"\u003cp\u003eHortusFox versions prior to 6.2 are affected by a remote code execution vulnerability located within the ThemeModule::startImport() function. The vulnerability stems from an insecure file handling implementation where uploaded ZIP archives are extracted directly into the application's public web root. Critically, the system performs no validation on the file names, extensions, or content of the extracted files prior to placement in an executable directory. An authenticated administrator can leverage this by uploading a specially crafted theme archive containing both a malicious PHP script and an .htaccess file, which bypasses typical execution restrictions. By subsequently requesting the uploaded file via the themes directory, an attacker can execute arbitrary OS commands under the privileges of the web-server user.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAuthenticated attacker logs into the HortusFox administrative interface.\u003c/li\u003e\n\u003cli\u003eAttacker prepares a ZIP archive containing a PHP web shell and a custom .htaccess configuration file.\u003c/li\u003e\n\u003cli\u003eAttacker navigates to the theme import feature and uploads the crafted ZIP archive.\u003c/li\u003e\n\u003cli\u003eThe application processes the upload through the vulnerable ThemeModule::startImport() function.\u003c/li\u003e\n\u003cli\u003eThe application extracts the contents of the ZIP archive directly into the public web root directory without validation.\u003c/li\u003e\n\u003cli\u003eThe .htaccess file is applied by the web server, enabling PHP execution for the attacker's script if previously restricted.\u003c/li\u003e\n\u003cli\u003eAttacker requests the path to the uploaded PHP shell via a standard HTTP GET request.\u003c/li\u003e\n\u003cli\u003eWeb server executes the PHP script, providing the attacker with remote command execution capabilities.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability allows an authenticated administrator to achieve full remote code execution on the underlying server. This results in complete compromise of the web application, potential lateral movement within the network, and access to sensitive data stored on or accessible to the web server process. The scope is limited to HortusFox instances running version 6.1 or earlier.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eUpgrade all HortusFox installations to version 6.2 or later immediately to patch the vulnerable ThemeModule::startImport() function.\u003c/li\u003e\n\u003cli\u003eImplement strict file system permissions on the public web root to prevent the web server process from writing new executable files in directories where they are not required.\u003c/li\u003e\n\u003cli\u003eDeploy file integrity monitoring on the /themes directory to alert on the creation of unexpected .php or .htaccess files.\u003c/li\u003e\n\u003cli\u003eEnable and monitor web server access logs for requests to non-standard or unexpected files within the /themes directory structure.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-10-06T16:56:30Z","date_published":"2026-10-06T16:56:30Z","id":"https://feed.craftedsignal.io/briefs/2026-10-cve-2026-104069/","summary":"HortusFox versions prior to 6.2 are vulnerable to remote code execution via an insufficient validation flaw in the theme import process allowing arbitrary file uploads to the web root.","title":"Remote Code Execution in HortusFox ThemeModule","url":"https://feed.craftedsignal.io/briefs/2026-10-cve-2026-104069/"}],"language":"en","title":"CraftedSignal Threat Feed - HortusFox (\u003c 6.2)","version":"https://jsonfeed.org/version/1.1"}