CVE-2026-108100
Description
HortusFox (hortusfox-web) before 6.2 contains an SQL injection vulnerability that allows API token holders to inject SQL by supplying crafted include_info values to the /api/locations/list endpoint. Attackers can place subqueries in include_info, which PlantsModel::getSpecificInfo() concatenates into the column list, to read any database table including user password hashes.
Predictions
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
No mitigations published for this CVE yet.
The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or — if you've already worked around this in production — publish your fix to the community-verified tier.
Propose a mitigation on Community Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here withsource_tier=community-verified.
References
- https://github.com/danielbrendel/hortusfox-web
- https://github.com/danielbrendel/hortusfox-web/blob/v6.1/app/controller/api.php#L642-L650
- https://github.com/danielbrendel/hortusfox-web/blob/v6.1/app/models/PlantsModel.php#L1026-L1033
- https://github.com/danielbrendel/hortusfox-web/commit/c0c0f4057dd8376b63c34028de36c8c6b6288fee
- https://github.com/danielbrendel/hortusfox-web/security/advisories/GHSA-4w8p-x2jj-42w7
- https://www.vulncheck.com/advisories/hortusfox-before-6.2-sql-injection-via-api-locations-list-include-info-parameter
CWEs
CWE-89
Community-verified mitigations for this CVE will appear above when contributors publish them.
Verify integrity in audit chain (admin only). AS-IS.