Junglewise Threat Intelligence

CVE-2025-45315: HortusFox hortusfox-web reflected XSS in admin.php email parameter

CVE-2025-45315 · Severity: medium · CVSS 5.4 · Published 2025-08-13

Technologies: Hortusfox. Vendors: Hortusfox.

Executive brief

HortusFox, a self-hosted plant management system, contains a security flaw in its administrative user-creation feature. An attacker can craft a malicious email address that, when it fails validation, executes unauthorized code in the administrator's web browser. This could allow for unauthorized actions to be performed in the context of the administrator's session, though the impact is limited to the user who submits the malicious data.

Technical details

A reflected cross-site scripting (XSS) vulnerability exists in the `create_user()` method within `app/controller/admin.php` of HortusFox-web v4.4. The application catches exceptions during user creation and passes the raw exception message—which includes the unsanitized `email` input—directly into a `FlashMessage` displayed to the user. An attacker with administrative privileges can inject a JavaScript payload into the `email` parameter; if a validation error occurs (such as a duplicate email), the payload is executed in the context of the administrator's browser. While this requires authenticated access and primarily affects the submitting user, it represents a failure to sanitize input echoed back in error states.

Affected products

  • HortusFox hortusfox-web 4.4

Timeline

  • 2025-08-13: advisory: NVD publication date

References

Related threats