Unrated severityNVD Advisory· Published Aug 13, 2025· Updated Aug 13, 2025
CVE-2025-45316
CVE-2025-45316
Description
A cross-site scripting (XSS) vulnerability in the TextBlockModule.php component of hortusfox-web v4.4 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the name parameter.
Affected products
2- hortusfox-web/hortusfox-webdescription
- Range: =4.4
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
5- github.com/chrisWalker11/Cves/blob/main/CVE-2025-45316/CVE-2025-45316.mdmitre
- github.com/danielbrendel/hortusfox-web/blob/8ab851101a62d8eb311235c118eeeb32a9b36978/app/models/ChatMsgModel.phpmitre
- github.com/danielbrendel/hortusfox-web/blob/8ab851101a62d8eb311235c118eeeb32a9b36978/app/modules/TextBlockModule.phpmitre
- github.com/danielbrendel/hortusfox-web/blob/8ab851101a62d8eb311235c118eeeb32a9b36978/app/modules/TextBlockModule.phpmitre
- github.com/danielbrendel/hortusfox-web/blob/8ab851101a62d8eb311235c118eeeb32a9b36978/app/views/chat.phpmitre
News mentions
0No linked articles in our index yet.