CVE-2024-57329: XSS
Published Jan 23, 2025
·Updated
HortusFox v3.9 contains a stored XSS vulnerability in the "Add Plant" function. The name input field does not sanitize or escape user inputs, allowing attackers to inject and execute arbitrary JavaScript payloads.
Affected Software
2 affected components
HortusFox hortusfox
HortusFox hortusfox=3.9
Event History
Jan 23, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·10:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
Does exploitation require an authenticated account or victim interaction?
Yes. The CVSS vector indicates an attacker needs low-level privileges and user interaction to exploit the issue; it is not rated as an unauthenticated attack.
2
Which HortusFox version is identified as affected?
The reported affected version is HortusFox v3.9. The provided information does not establish whether earlier or later versions are affected.
3
What security impact is indicated by the CVSS assessment?
The vulnerability is rated medium severity at 5.4. The assessment indicates low confidentiality and integrity impact, no availability impact, and a scope change.