CVE-2024-57329
23.01.2025, 22:15
HortusFox v3.9 contains a stored XSS vulnerability in the "Add Plant" function. The name input field does not sanitize or escape user inputs, allowing attackers to inject and execute arbitrary JavaScript payloads.
Awaiting analysis
This vulnerability is currently awaiting analysis.