{"id":"CVE-2026-108100","title":"HortusFox (hortusfox-web) before 6.2 contains an SQL injection vulnerability that allows API token holders to inject SQL by supplying crafted include_info values to the /api/locations/list endpoint","summary":"HortusFox (hortusfox-web) before 6.2 contains an SQL injection vulnerability that allows API token holders to inject SQL by supplying crafted include_info values to the /api/locations/list endpoint. Attackers can place subqueries in incl…","severity":"medium","cvss":6.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","cwe":["CWE-89"],"published":"2026-10-09","updated":"2026-10-09","sourceUpdated":"2026-10-09T15:17:10.583","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-108100","references":[{"url":"https://github.com/danielbrendel/hortusfox-web","label":"disclosure@vulncheck.com"},{"url":"https://github.com/danielbrendel/hortusfox-web/blob/v6.1/app/controller/api.php#L642-L650","label":"disclosure@vulncheck.com"},{"url":"https://github.com/danielbrendel/hortusfox-web/blob/v6.1/app/models/PlantsModel.php#L1026-L1033","label":"disclosure@vulncheck.com"},{"url":"https://github.com/danielbrendel/hortusfox-web/commit/c0c0f4057dd8376b63c34028de36c8c6b6288fee","label":"disclosure@vulncheck.com"},{"url":"https://github.com/danielbrendel/hortusfox-web/security/advisories/GHSA-4w8p-x2jj-42w7","label":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/hortusfox-before-6.2-sql-injection-via-api-locations-list-include-info-parameter","label":"disclosure@vulncheck.com"}],"tags":["nvd"],"ingestedAt":"2026-10-09T16:02:33.378Z","slug":"CVE-2026-108100","body":"## Overview\n\nHortusFox (hortusfox-web) before 6.2 contains an SQL injection vulnerability that allows API token holders to inject SQL by supplying crafted include_info values to the /api/locations/list endpoint. Attackers can place subqueries in include_info, which PlantsModel::getSpecificInfo() concatenates into the column list, to read any database table including user password hashes.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":36,"depthScoreParts":{"impact":35.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}