CVE-2024-57329
EUVD-2024-5356523.01.2025, 22:15
HortusFox v3.9 contains a stored XSS vulnerability in the "Add Plant" function. The name input field does not sanitize or escape user inputs, allowing attackers to inject and execute arbitrary JavaScript payloads.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| hortusfox | hortusfox | 3.9 |
𝑥
= Vulnerable software versions