Executive brief
HortusFox, a self-hosted plant management system, contains a security flaw in its task creation feature. An attacker can create a task with a malicious name that, when viewed by other users or administrators in the system chat, executes unauthorized code in their browser. This could allow an attacker to steal login sessions, perform actions on behalf of other users, or compromise administrative accounts.
Technical details
A stored Cross-Site Scripting (XSS) vulnerability exists in the 'create task' functionality of hortusfox-web v4.4. The root cause is the lack of sanitization of the $name (task title) variable in the createdTask() method, which is subsequently passed to addToChat() and inserted into the database via a raw SQL query without HTML escaping. When the application broadcasts the new-task message to the system chat, the unescaped payload is rendered in the browsers of all connected users. An attacker can exploit this by injecting a malicious payload (e.g., using <img> tags with onerror attributes) into the task title. This can lead to session hijacking, CSRF token theft, or privilege escalation if an administrator views the chat.
Affected products
- hortusfox hortusfox-web 4.4
Timeline
- 2025-08-13: advisory: Initial NVD publication
- 2025-08-13: disclosed: External researcher disclosure via GitHub