Impact
A stored cross‑site scripting flaw exists in HortusFox version 5.9. The flaw arises because plant notes are rendered with Parsedown without safe mode, allowing authenticated workspace members to embed persistent JavaScript. When a malicious note is viewed, the script executes in the browser of every user who opens that plant, enabling an attacker to steal session cookies or perform privileged operations as those users, including administrators.
Affected Systems
The vulnerability affects only the Daniel Brendel HortusFox application, specifically version 5.9. All authenticated workspace members who can create or edit plant notes are capable of injecting the malicious script. Any user who subsequently views the affected plant will have the browser execute the injected code.
Risk and Exploitability
The CVSS score of 5.4 indicates a moderate severity. No EPSS score is available, and the flaw is not listed in CISA's KEV catalog, so there is no evidence of widespread exploitation yet. The attacker must be an authenticated workspace member to inject the script, but once the script runs, it can hijack sessions or act on behalf of any viewer, including administrators. The combination of broad impact on unescaped note viewers and the ability to attain administrative privileges through session theft makes the risk significant, even though the current exploitation potential remains low to moderate.
OpenCVE Enrichment