Medium severity6.5NVD Advisory· Published Oct 9, 2026· Updated Oct 9, 2026
CVE-2026-108100
CVE-2026-108100
Description
HortusFox (hortusfox-web) before 6.2 contains an SQL injection vulnerability that allows API token holders to inject SQL by supplying crafted include_info values to the /api/locations/list endpoint. Attackers can place subqueries in include_info, which PlantsModel::getSpecificInfo() concatenates into the column list, to read any database table including user password hashes.
Affected products
2- Range: <6.2
Patches
Vulnerability mechanics
References
5- github.com/danielbrendel/hortusfox-web/blob/v6.1/app/controller/api.phpnvd
- github.com/danielbrendel/hortusfox-web/blob/v6.1/app/models/PlantsModel.phpnvd
- github.com/danielbrendel/hortusfox-web/commit/c0c0f4057dd8376b63c34028de36c8c6b6288feenvd
- github.com/danielbrendel/hortusfox-web/security/advisories/GHSA-4w8p-x2jj-42w7nvd
- www.vulncheck.com/advisories/hortusfox-before-6.2-sql-injection-via-api-locations-list-include-info-parameternvd
News mentions
0No linked articles in our index yet.