Sceawere

Vulnerability Detail

CVE-2026-104069UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

HortusFox Theme Import RCE

Vulnerability Metadata

Severity
High
Score / CVSS
7.2
Creation Date
10h ago
Vendor
danielbrendel
Product
hortusfox-web
Attack Type
Unrestricted Upload of File with Dangerous Type
Vector String
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

HortusFox before 6.2 contains a remote code execution vulnerability in ThemeModule::startImport() where an uploaded ZIP archive is extracted directly into the public web root before any validation of file names, extensions, or content is performed. An authenticated administrator can upload a crafted theme archive containing a PHP file and an .htaccess file to re-enable execution, then request it under the themes directory to execute arbitrary OS commands as the web-server user.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.2",
  "pubDate": "2026-10-06T15:17:12.237Z",
  "pubdate": "2026-10-06T15:17:12.237Z",
  "executiveSummary": "HortusFox versions prior to 6.2 are susceptible to a critical Remote Code Execution (RCE) vulnerability stemming from improper input validation during the theme import process.\nThe vulnerability resides in the ThemeModule::startImport() function, which fails to perform security checks on uploaded ZIP archives.\nAn authenticated administrator can exploit this flaw by uploading a malicious archive containing executable PHP scripts and configuration directives, such as .htaccess files.\nSuccessful exploitation allows an attacker to bypass file-type restrictions and achieve arbitrary command execution under the context of the web-server user.\nThe impact includes full server compromise, potential data exfiltration, and unauthorized system administration.\nExploitation requires authenticated administrative access to the platform, making the risk profile dependent on the security of administrator credentials and session integrity.",
  "technicalDetails": "The vulnerability exists within the ThemeModule::startImport() function of the HortusFox codebase. The application's design facilitates the extraction of theme-related ZIP archives directly into the public web root directory without implementing prior validation logic concerning file name, extension, or content integrity.\nThe attack flow initiates when an authenticated administrator interacts with the theme import feature. Because the application lacks a sanitization layer for archive contents, an attacker can craft a ZIP file containing a malicious PHP webshell and a custom .htaccess configuration file. The .htaccess file is specifically designed to override web server directory security settings, explicitly re-enabling PHP execution if the server environment would otherwise restrict it in the target directory.\nDuring the extraction process, the application writes these files into the themes directory. By design, this directory is accessible via standard HTTP requests. Once the files are successfully written to the public web root, the attacker performs a targeted GET request to the path where the PHP script was extracted. The web server interprets the uploaded file as a valid script, executing arbitrary OS commands with the permissions of the web-server user process.\nThis vulnerability is rooted in an 'Unrestricted Upload of File with Dangerous Type' pattern. The failure to validate the archive's internal contents before filesystem placement allows for Directory Traversal or direct placement of executable code into web-accessible locations. Since the application performs no validation of the ZIP structure, it blindly trusts the contents provided by the administrator account, bypassing any inherent security controls meant to isolate theme assets from executable application logic.\nThe post-exploitation impact allows the attacker to transition from simple code execution to persistent backdooring, lateral movement within the underlying server infrastructure, or complete takeover of the application database and configuration files. Given that the web server environment generally has access to the application's environment variables and database credentials, this RCE effectively provides the attacker with administrative control over the entire HortusFox instance and the underlying operating system environment."
}
CVE-2026-104069: HortusFox Theme Import RCE (HIGH Severity, CVSS: 7.2) | Sceawere