HortusFox v3.9 contains a stored XSS vulnerability in the "Add Plant" function. The name input field does not sanitize or escape user inputs, allowing attackers to inject and execute arbitrary JavaScript payloads.
CVSS
No CVSS.
References
| Link | Resource |
|---|---|
| https://github.com/fatihtuzunn/CVEs/tree/main/CVE-2024-57329 | Exploit Third Party Advisory |
Configurations
History
14 Aug 2025, 20:59
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:hortusfox:hortusfox:3.9:*:*:*:*:*:*:* | |
| First Time |
Hortusfox hortusfox
Hortusfox |
|
| References | () https://github.com/fatihtuzunn/CVEs/tree/main/CVE-2024-57329 - Exploit, Third Party Advisory |
23 Jan 2025, 22:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-01-23 22:15
Updated : 2025-08-14 20:59
NVD link : CVE-2024-57329
Mitre link : CVE-2024-57329
JSON object : View
Products Affected
hortusfox
- hortusfox
CWE
No CWE.
