PT-2026-106051 · Neorazorx · Facturascripts

·

CVE-2026-104905

·

Published

2026-10-05

·

Updated

2026-10-05

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
FacturaScripts before version 2026.7 contains a PHP object injection vulnerability in WidgetSelect::processFormData() that allows authenticated attackers to trigger unserialize() on raw POST data without an allowed classes filter for multiple-select fields. Attackers can submit a serialized XLSXWriter object as the field value to invoke its destruct() method, deleting arbitrary attacker-specified files such as config.php or backup data, resulting in denial of service and potential application reinstall hijack.

Exploit

Fix

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-104905

Affected Products

Facturascripts