CVE-2026-104905
Received Received - Intake

PHP Object Injection in FacturaScripts

Vulnerability report for CVE-2026-104905, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-05

Last updated on: 2026-10-05

Assigner: VulnCheck

Description

FacturaScripts before version 2026.7 contains a PHP object injection vulnerability in WidgetSelect::processFormData() that allows authenticated attackers to trigger unserialize() on raw POST data without an allowed_classes filter for multiple-select fields. Attackers can submit a serialized XLSXWriter object as the field value to invoke its __destruct() method, deleting arbitrary attacker-specified files such as config.php or backup data, resulting in denial of service and potential application reinstall hijack.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-05
Last Modified
2026-10-05
Generated
2026-10-05
AI Q&A
2026-10-05
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
NeoRazorX facturascripts 2025.7

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-502 The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a PHP object injection flaw in FacturaScripts versions before 2026.7. It occurs in the WidgetSelect::processFormData() function where raw POST data is passed to unserialize() without proper filtering. Attackers can submit a serialized XLSXWriter object to trigger its __destruct() method, which deletes arbitrary files like config.php or backups.

Detection Guidance

Check FacturaScripts versions before 2026.7 for the WidgetSelect::processFormData() vulnerability. Look for unauthorized file deletions or suspicious POST requests to multiple-select fields. Monitor server logs for unserialize() calls without allowed_classes filtering.

Impact Analysis

An authenticated attacker with access to a form containing a multiple-select field can exploit this to delete critical files, causing denial of service, data loss, or system hijacking. This may require reinstalling the application if config.php is deleted.

Compliance Impact

This vulnerability could lead to unauthorized file deletion, including critical configuration files like config.php, which may result in data loss or system compromise. For GDPR, this could violate integrity and availability principles (Article 5) if personal data is affected. For HIPAA, unauthorized file deletion or system disruption could impact data integrity and availability, potentially violating Security Rule requirements.

Mitigation Strategies

Upgrade FacturaScripts to version 2026.7 or later immediately. Remove write permissions from web server users to critical files like config.php. Implement input validation for POST data and restrict allowed_classes in unserialize() calls.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-104905. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart