CVE-2026-108100: HortusFox before 6.2 SQL Injection via /api/locations/list include_info Parameter
HortusFox (hortusfox-web) before 6.2 contains an SQL injection vulnerability that allows API token holders to inject SQL by supplying crafted includeinfo values to the /api/locations/list endpoint. Attackers can place subqueries in includeinfo, which PlantsModel::getSpecificInfo() concatenates into the column list, to read any database table including user password hashes.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker needs a valid API token. The vulnerable endpoint is network-accessible, and no user interaction is required.
What information could be exposed?
Crafted include_info values can inject subqueries into the SQL column list. This can allow reading arbitrary database tables, including user password hashes.
Which deployments are affected?
HortusFox hortusfox-web versions before 6.2 are affected. Deployments where API tokens are available to untrusted or lower-privileged users are exposed to token holders.