FacturaScripts before version 2026.7 contains a PHP object injection vulnerability in WidgetSelect::processFormData() that allows authenticated attackers to trigger unserialize() on raw POST data without an allowed_classes filter for multiple-select fields. Attackers can submit a serialized XLSXWriter object as the field value to invoke its __destruct() method, deleting arbitrary attacker-specified files such as config.php or backup data, resulting in denial of service and potential application reinstall hijack.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Mon, 05 Oct 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | FacturaScripts before version 2026.7 contains a PHP object injection vulnerability in WidgetSelect::processFormData() that allows authenticated attackers to trigger unserialize() on raw POST data without an allowed_classes filter for multiple-select fields. Attackers can submit a serialized XLSXWriter object as the field value to invoke its __destruct() method, deleting arbitrary attacker-specified files such as config.php or backup data, resulting in denial of service and potential application reinstall hijack. | |
| Title | FacturaScripts < 2026.7 PHP Object Injection via WidgetSelect | |
| First Time appeared |
Neorazorx
Neorazorx facturascripts |
|
| Weaknesses | CWE-502 | |
| CPEs | cpe:2.3:a:neorazorx:facturascripts:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Neorazorx
Neorazorx facturascripts |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-10-05T17:34:18.285Z
Reserved: 2026-10-02T15:43:45.338Z
Link: CVE-2026-104905
No data.
No data.
No data.
OpenCVE Enrichment
No data.
Weaknesses