天下漏洞,尽知其名
MEDIUM

CVE-2026-108100 HortusFox SQL 注入漏洞

影响持有 API 令牌的攻击者可读取任意数据库表,包括用户密码哈希

AI 研判

HortusFox(hortusfox-web)6.2 之前版本存在 SQL 注入漏洞。攻击者通过向 /api/locations/list 接口传入特制的 include_info 值,将子查询注入到 SQL 语句的列名列表中。该漏洞可导致任意数据库表数据被读取,包括用户密码哈希。

影响范围

HortusFox

HortusFox(hortusfox-web)6.2 之前的版本受影响,具体受影响版本范围暂无更详细的公开信息。

漏洞详情

漏洞类型为 SQL 注入,成因是 PlantsModel::getSpecificInfo() 将 include_info 参数直接拼接进 SQL 查询的列名列表,未做参数化或白名单校验。持有有效 API 令牌的攻击者可在 include_info 中构造子查询,从而在列位置执行任意 SQL 并回显数据。利用方式为向 /api/locations/list 发送带恶意 include_info 的请求。

利用条件与风险

利用前提是攻击者需持有有效的 API 令牌,属于需认证的注入漏洞。成功利用后可读取任意数据库表,包括用户密码哈希,可能导致账户接管与横向渗透。

修复建议

建议升级至 HortusFox 6.2 或更高版本。临时缓解措施包括限制 API 令牌的发放与权限、对 include_info 参数进行严格白名单校验,暂无其他公开信息。

原始情报

HortusFox (hortusfox-web) before 6.2 contains an SQL injection vulnerability that allows API token holders to inject SQL by supplying crafted include_info values to the /api/locations/list endpoint. Attackers can place subqueries in include_info, which PlantsModel::getSpecificInfo() concatenates into the column list, to read any database table including user password hashes.