PT-2026-38611 · Neorazorx+1 · Facturascripts+1
Published
2026-05-07
·
Updated
2026-05-19
·
CVE-2026-27892
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
FacturaScripts versions prior to 2026
Description
A sensitive information disclosure issue exists in the Library module of FacturaScripts. The application stores and serves uploaded images byte-for-byte without stripping EXIF, XMP, or IPTC metadata. This allows any authenticated user who downloads an image to extract the uploader's embedded metadata, which may include GPS coordinates, device information, timestamps, embedded comments, notes, thumbnail previews, and other personally identifiable information (PII). In real-world scenarios, this could lead to the disclosure of an employee's precise home address if they upload a photo taken at their residence.
Recommendations
Update to version 2026.
As a temporary workaround, restrict access to the Library module to minimize the risk of unauthorized metadata extraction.
Exploit
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Facturascripts
Facturascripts/Facturascripts