Executive brief
HortusFox, a self-hosted plant management system, contains a security flaw in its administrative user-creation feature. An attacker can craft a malicious email address that, when it fails validation, executes unauthorized code in the administrator's web browser. This could allow for unauthorized actions to be performed in the context of the administrator's session, though the impact is limited to the user who submits the malicious data.
Technical details
A reflected cross-site scripting (XSS) vulnerability exists in the `create_user()` method within `app/controller/admin.php` of HortusFox-web v4.4. The application catches exceptions during user creation and passes the raw exception message—which includes the unsanitized `email` input—directly into a `FlashMessage` displayed to the user. An attacker with administrative privileges can inject a JavaScript payload into the `email` parameter; if a validation error occurs (such as a duplicate email), the payload is executed in the context of the administrator's browser. While this requires authenticated access and primarily affects the submitting user, it represents a failure to sanitize input echoed back in error states.
Affected products
- HortusFox hortusfox-web 4.4
Timeline
- 2025-08-13: advisory: NVD publication date