PT-2026-38611 · Neorazorx+1 · Facturascripts+1

Published

2026-05-07

·

Updated

2026-05-19

·

CVE-2026-27892

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions FacturaScripts versions prior to 2026
Description A sensitive information disclosure issue exists in the Library module of FacturaScripts. The application stores and serves uploaded images byte-for-byte without stripping EXIF, XMP, or IPTC metadata. This allows any authenticated user who downloads an image to extract the uploader's embedded metadata, which may include GPS coordinates, device information, timestamps, embedded comments, notes, thumbnail previews, and other personally identifiable information (PII). In real-world scenarios, this could lead to the disclosure of an employee's precise home address if they upload a photo taken at their residence.
Recommendations Update to version 2026. As a temporary workaround, restrict access to the Library module to minimize the risk of unauthorized metadata extraction.

Exploit

Fix

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2026-27892
GHSA-Q7F2-RV22-2XGR

Affected Products

Facturascripts
Facturascripts/Facturascripts