CVE-2024-57329

MEDIUM

HortusFox 3.9 - Stored Cross-Site Scripting in Add Plant Name Input

Title source: llm
STIX 2.1

Description

HortusFox v3.9 contains a stored XSS vulnerability in the "Add Plant" function. The name input field does not sanitize or escape user inputs, allowing attackers to inject and execute arbitrary JavaScript payloads.

References (1)

Core 1

Scores

CVSS v3 5.4
EPSS 0.0025
EPSS Percentile 16.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (1)
hortusfox/hortusfox 3.9
Published Jan 23, 2025
Tracked Since Feb 18, 2026