Sceawere
Vulnerability Detail
CVE-2026-104905UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
FacturaScripts PHP Object Injection Vulnerability
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 8.1
- Creation Date
- 4h ago
- Vendor
- NeoRazorX
- Product
- facturascripts
- Attack Type
- CWE-502
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
FacturaScripts before version 2026.7 contains a PHP object injection vulnerability in WidgetSelect::processFormData() that allows authenticated attackers to trigger unserialize() on raw POST data without an allowed_classes filter for multiple-select fields. Attackers can submit a serialized XLSXWriter object as the field value to invoke its __destruct() method, deleting arbitrary attacker-specified files such as config.php or backup data, resulting in denial of service and potential application reinstall hijack.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "8.1",
"pubDate": "2026-10-05T18:17:31.623Z",
"pubdate": "2026-10-05T18:17:31.623Z",
"executiveSummary": "FacturaScripts versions prior to 2026.7 are susceptible to a critical PHP object injection vulnerability located within the WidgetSelect::processFormData() method. This vulnerability arises from the insecure deserialization of user-supplied POST data in multiple-select fields.\nAn authenticated attacker can leverage this flaw to instantiate arbitrary PHP objects, specifically targeting the XLSXWriter class. By providing a crafted serialized payload, an attacker can invoke the object's __destruct() magic method to perform unauthorized file system operations.\nThe primary impact of this vulnerability is a high-severity Denial of Service (DoS) through the deletion of critical system files, including 'config.php' or application backup data. Furthermore, the ability to delete configuration files enables an attacker to hijack the application installation process, potentially leading to unauthorized administrative control over the affected instance.\nExploitation requires the attacker to be authenticated, though the simplicity of the attack vector makes it a significant risk for environments where user accounts may be compromised or restricted. Organizations using affected versions of FacturaScripts are urged to upgrade to version 2026.7 or higher immediately.",
"technicalDetails": "The root cause of this vulnerability lies in the improper handling of user input within the 'WidgetSelect::processFormData()' function. The application accepts raw POST data for multiple-select fields and passes this input directly into the 'unserialize()' function without applying an 'allowed_classes' filter.\nPHP object injection occurs when an attacker provides a serialized string representing a class present within the application's codebase. In this specific scenario, the attacker injects a serialized 'XLSXWriter' object. Because the application does not validate the class being instantiated, the PHP engine proceeds to recreate the object from the provided stream.\nThe exploitation flow is as follows: 1) The attacker identifies a target multiple-select field that triggers 'WidgetSelect::processFormData()'. 2) The attacker crafts a malicious serialized string containing the 'XLSXWriter' class definition, configured with properties that control the execution of its '__destruct()' method. 3) The attacker submits this payload via a POST request. 4) Upon completion of the script execution, the PHP engine automatically invokes the destructor of the injected 'XLSXWriter' object. 5) The destructor logic, if improperly sanitized, executes file deletion operations directed at sensitive target paths.\nBy manipulating the object properties, an attacker can achieve arbitrary file deletion. Targeting 'config.php' is particularly effective, as its removal forces the application into an unconfigured state, allowing the attacker to re-run the installation wizard and establish administrative credentials. This effectively facilitates a full application takeover.\nThe vulnerability is restricted to versions prior to 2026.7. Successful exploitation requires an authenticated session, meaning an attacker must already have access to the application via an authorized account. The vulnerability is triggered entirely server-side, requiring no specific network exposure beyond the standard web interface access. The lack of white-listing or black-listing on the unserialization process constitutes a critical design flaw in input handling."
}