CVE-2024-57329 – HortusFox Stored Cross-Site Scripting (XSS) Vulnerability

The following table lists the changes that have been made to the
CVE-2024-57329 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution
of a vulnerability, and for identifying the most recent changes that may
impact the vulnerability’s severity, exploitability, or other characteristics.

  • New CVE Received
    by [email protected]

    Jan. 23, 2025

    Action Type Old Value New Value
    Added Description HortusFox v3.9 contains a stored XSS vulnerability in the “Add Plant” function. The name input field does not sanitize or escape user inputs, allowing attackers to inject and execute arbitrary JavaScript payloads.
    Added Reference https://github.com/fatihtuzunn/CVEs/tree/main/CVE-2024-57329
Share the Post:

Related Posts