Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 05 Oct 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 05 Oct 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | FacturaScripts before version 2026.7 contains a PHP object injection vulnerability in WidgetSelect::processFormData() that allows authenticated attackers to trigger unserialize() on raw POST data without an allowed_classes filter for multiple-select fields. Attackers can submit a serialized XLSXWriter object as the field value to invoke its __destruct() method, deleting arbitrary attacker-specified files such as config.php or backup data, resulting in denial of service and potential application reinstall hijack. | |
| Title | FacturaScripts < 2026.7 PHP Object Injection via WidgetSelect | |
| First Time appeared |
Neorazorx
Neorazorx facturascripts |
|
| Weaknesses | CWE-502 | |
| CPEs | cpe:2.3:a:neorazorx:facturascripts:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Neorazorx
Neorazorx facturascripts |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-10-05T18:01:58.256Z
Reserved: 2026-10-02T15:43:45.338Z
Link: CVE-2026-104905
Updated: 2026-10-05T18:01:43.215Z
Status : Received
Published: 2026-10-05T18:17:31.623
Modified: 2026-10-05T19:17:15.163
Link: CVE-2026-104905
No data.
OpenCVE Enrichment
Updated: 2026-10-05T19:00:13Z
-
CWE-502
Deserialization of Untrusted Data