ZeroHour

CVE-2024-57329

PoC
CVSS 3.1
5.4 medium
EPSS
<1%p18
Published
()
Modified
Description

HortusFox v3.9 contains a stored XSS vulnerability in the "Add Plant" function. The name input field does not sanitize or escape user inputs, allowing attackers to inject and execute arbitrary JavaScript payloads.

Vendors
hortusfox
Products
hortusfox
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.