danielbrendel/hortusfox-web

danielbrendel/hortusfox-web

Releases43
Frequency2 weeks 6 days
Last Release
Stars1.56K
Self-hosted collaborative plant management and tracking system for plant enthusiasts

CVE History

CVEPublishedCVSS v3CVSS v2
6.1 MEDIUM

A cross-site scripting (XSS) vulnerability in the /Calendar endpoint of hortusfox-web v4.4 allows attackers to execute arbitrary JavaScript in the context of a user's browser via a crafted payload injected into the add function.

5.4 MEDIUM

A cross-site scripting (XSS) vulnerability in the /controller/admin.php endpoint of hortusfox-web v4.4 allows attackers to execute arbitrary JavaScript in the context of a user's browser via a crafted payload injected into the email parameter.

6.1 MEDIUM

A cross-site scripting (XSS) vulnerability in the TextBlockModule.php component of hortusfox-web v4.4 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the name parameter.

6.5 MEDIUM

A zip slip vulnerability in the /modules/ImportModule.php component of hortusfox-web v4.4 allows attackers to execute arbitrary code via a crafted archive.