CVE-2026-108101: HortusFox through 6.3 Unrestricted File Upload via Plant Attachments
HortusFox (hortusfox-web) through 6.3 contains an unrestricted file upload vulnerability in PlantAttachmentModel that allows authenticated users to store files with client-supplied extensions under public/attachments/. Attackers can upload HTML or SVG files via /plants/attachments/add for stored cross-site scripting, or PHP files where .htaccess is unenforced to execute code.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker needs an authenticated HortusFox account with access to upload plant attachments through /plants/attachments/add. The available data does not identify any further role restriction.
When does an uploaded PHP file lead to server-side code execution?
PHP upload becomes code execution where the server does not enforce the .htaccess protection for the public/attachments/ directory. In that configuration, a PHP file stored in the attachment directory may be executed by the web server.
Are all deployments exposed to the same impact?
No. HTML or SVG uploads can be used for stored cross-site scripting, while PHP uploads require an environment in which .htaccess is unenforced to execute code. The vulnerability affects HortusFox through version 6.3.