HortusFox before 6.2 contains a remote code execution vulnerability in ThemeModule::startImport() where an uploaded ZIP archive is extracted directly into the public web root before any validation of file names, extensions, or content is performed. An authenticated administrator can upload a crafted theme archive containing a PHP file and an .htaccess file to re-enable execution, then request it under the themes directory to execute arbitrary OS commands as the web-server user.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 06 Oct 2026 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | HortusFox before 6.2 contains a remote code execution vulnerability in ThemeModule::startImport() where an uploaded ZIP archive is extracted directly into the public web root before any validation of file names, extensions, or content is performed. An authenticated administrator can upload a crafted theme archive containing a PHP file and an .htaccess file to re-enable execution, then request it under the themes directory to execute arbitrary OS commands as the web-server user. | |
| Title | HortusFox < 6.2 Remote Code Execution via Theme Import | |
| Weaknesses | CWE-434 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-10-06T16:09:16.923Z
Reserved: 2026-10-01T18:02:50.082Z
Link: CVE-2026-104069
No data.
Status : Deferred
Published: 2026-10-06T15:17:12.237
Modified: 2026-10-06T15:17:12.357
Link: CVE-2026-104069
No data.
OpenCVE Enrichment
No data.
Weaknesses