Product
HortusFox hortusfox-web through version 6.3 is vulnerable to unrestricted file uploads in the PlantAttachmentModel, allowing authenticated attackers to execute remote code or perform stored cross-site scripting.