CVE-2026-108100EPSS p17.5%
CVE-2026-108100CVE-2026-108100
Description
HortusFox (hortusfox-web) before 6.2 contains an SQL injection vulnerability that allows API token holders to inject SQL by supplying crafted include_info values to the /api/locations/list endpoint. Attackers can place subqueries in include_info, which PlantsModel::getSpecificInfo() concatenates into the column list, to read any database table including user password hashes.
Scoring
| CVSS | 6.5 () |
| Vector | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
| EPSS | 0.27% probability of exploitation · percentile 17.5% · 2026-10-10T12:00:23Z |
| Last modified | 2026-10-09 |