Impact
A flaw in HortusFox-Web prior to version 6.1 allows an authenticated administrator to execute arbitrary operating‑system commands by abusing the Import/Export feature. This flaw is classified as CWE‑434, a file upload weakness that permits dangerous file handling. The ability to run arbitrary commands as the web server user could lead to full compromise of the underlying application server host, including data theft, defacement, or the deployment of additional malware.
Affected Systems
The affected product is HortusFox‑Web provided by Daniel Brendel, specifically all releases before v6.1. The vulnerability exists in every instance where the Import/Export functionality remains enabled in these versions, regardless of deployment environment.
Risk and Exploitability
The CVSS score of 8.6 indicates a high severity. The EPSS score of less than 1% suggests the likelihood of exploitation is currently low, and the flaw is not listed in CISA’s KEV catalog. Nevertheless, because the attack requires only administrator authentication—a role that is typically present in many installations—the risk to exposed or poorly segmented environments remains high. Attackers would authenticate, invoke the Import/Export operation, and supply a malicious payload that is executed by the web server process.
OpenCVE Enrichment