CVE-2024-57329

MEDIUM

Hortusfox - XSS

Title source: rule
STIX 2.1

Description

HortusFox v3.9 contains a stored XSS vulnerability in the "Add Plant" function. The name input field does not sanitize or escape user inputs, allowing attackers to inject and execute arbitrary JavaScript payloads.

References (1)

Core 1

Scores

CVSS v3 5.4
EPSS 0.0012
EPSS Percentile 30.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (1)
hortusfox/hortusfox 3.9
Published Jan 23, 2025
Tracked Since Feb 18, 2026