Junglewise Threat Intelligence

CVE-2025-45313: HortusFox hortusfox-web Stored XSS in Task Creation

CVE-2025-45313 · Severity: medium · CVSS 6.1 · Published 2025-08-13

Technologies: Hortusfox. Vendors: Hortusfox.

Executive brief

HortusFox, a self-hosted plant management system, contains a security flaw in its task creation feature. An attacker can create a task with a malicious name that, when viewed by other users or administrators in the system chat, executes unauthorized code in their browser. This could allow an attacker to steal login sessions, perform actions on behalf of other users, or compromise administrative accounts.

Technical details

A stored Cross-Site Scripting (XSS) vulnerability exists in the 'create task' functionality of hortusfox-web v4.4. The root cause is the lack of sanitization of the $name (task title) variable in the createdTask() method, which is subsequently passed to addToChat() and inserted into the database via a raw SQL query without HTML escaping. When the application broadcasts the new-task message to the system chat, the unescaped payload is rendered in the browsers of all connected users. An attacker can exploit this by injecting a malicious payload (e.g., using <img> tags with onerror attributes) into the task title. This can lead to session hijacking, CSRF token theft, or privilege escalation if an administrator views the chat.

Affected products

  • hortusfox hortusfox-web 4.4

Timeline

  • 2025-08-13: advisory: Initial NVD publication
  • 2025-08-13: disclosed: External researcher disclosure via GitHub

References

Related threats