{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/hortusfox-web--6.3/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:hortusfox:hortusfox_web:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-108101"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["hortusfox-web (\u003c= 6.3)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["HortusFox"],"content_html":"\u003cp\u003eHortusFox (hortusfox-web) versions through 6.3 contain an unrestricted file upload vulnerability in the PlantAttachmentModel. The application fails to properly validate the file extensions of user-supplied attachments when using the /plants/attachments/add endpoint. Authenticated users can upload arbitrary file types, which are subsequently stored in the public/attachments/ directory. If the underlying server environment lacks strict .htaccess enforcement or other execution restrictions, an attacker can upload and execute malicious PHP scripts to gain remote code execution. Additionally, the ability to upload HTML or SVG files permits stored cross-site scripting (XSS) attacks, which could be used to compromise the sessions of other authenticated users or administrators interacting with the application. Defenders should prioritize restricting upload directories and enforcing strict file extension allow-lists on the server side.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker authenticates to the HortusFox web application with valid user credentials.\u003c/li\u003e\n\u003cli\u003eAttacker navigates to the endpoint /plants/attachments/add for document management.\u003c/li\u003e\n\u003cli\u003eAttacker intercepts the file upload request to modify the file content and extension.\u003c/li\u003e\n\u003cli\u003eAttacker uploads a malicious PHP script or an HTML/SVG file containing XSS payloads.\u003c/li\u003e\n\u003cli\u003eThe application saves the file to the public/attachments/ directory without validating the extension.\u003c/li\u003e\n\u003cli\u003eAttacker requests the stored file via the browser or directly accesses the file URL.\u003c/li\u003e\n\u003cli\u003eThe server executes the uploaded PHP script or renders the HTML/SVG file in the context of the user session.\u003c/li\u003e\n\u003cli\u003eAttacker gains remote code execution on the web server or successfully executes unauthorized scripts in the browser.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows authenticated attackers to gain remote code execution (RCE) on the server, potentially leading to a full system compromise. Alternatively, attackers can perform stored XSS to hijack administrator sessions or perform actions on behalf of other users. This vulnerability impacts all installations of hortusfox-web versions 6.3 and earlier.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eUpgrade hortusfox-web to a version beyond 6.3 immediately to address the insecure validation in PlantAttachmentModel.\u003c/li\u003e\n\u003cli\u003eImplement server-side execution restrictions on the public/attachments/ directory, ensuring it is configured as a non-executable area (e.g., via web server configuration to disable PHP execution in this path).\u003c/li\u003e\n\u003cli\u003eDeploy a web application firewall (WAF) rule to block POST requests to /plants/attachments/add that contain suspicious file extensions or MIME types not associated with legitimate plant attachments.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-10-09T15:31:32Z","date_published":"2026-10-09T15:31:32Z","id":"https://feed.craftedsignal.io/briefs/2026-10-hortusfox-upload/","summary":"HortusFox hortusfox-web through version 6.3 is vulnerable to unrestricted file uploads in the PlantAttachmentModel, allowing authenticated attackers to execute remote code or perform stored cross-site scripting.","title":"Unrestricted File Upload in HortusFox hortusfox-web","url":"https://feed.craftedsignal.io/briefs/2026-10-hortusfox-upload/"}],"language":"en","title":"CraftedSignal Threat Feed - Hortusfox-Web (\u003c= 6.3)","version":"https://jsonfeed.org/version/1.1"}