HortusFox v3.9 contains a stored XSS vulnerability in the...
Moderate severity
Unreviewed
Published
Jan 24, 2025
to the GitHub Advisory Database
•
Updated Jan 25, 2025
Description
Published by the National Vulnerability Database
Jan 23, 2025
Published to the GitHub Advisory Database
Jan 24, 2025
Last updated
Jan 25, 2025
HortusFox v3.9 contains a stored XSS vulnerability in the "Add Plant" function. The name input field does not sanitize or escape user inputs, allowing attackers to inject and execute arbitrary JavaScript payloads.
References