PT-2026-38612 · Neorazorx+1 · Facturascripts+1
Published
2026-05-07
·
Updated
2026-05-19
·
CVE-2026-27964
CVSS v3.1
3.9
Low
| Vector | AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
FacturaScripts versions prior to 2025.8
Description
A Reflected Cross-Site Scripting (XSS) issue exists where the application reflects the value of the
fsNick cookie parameter directly into the HTML without sanitization or encoding into the Document Object Model (DOM). Although the server rejects the modified session and forces a logout, the HTML containing the payload reaches the browser first, allowing the script to execute immediately upon load and bypass the redirect.Recommendations
Update to version 2025.8.
As a temporary workaround, restrict or sanitize the use of the
fsNick cookie parameter to minimize the risk of exploitation.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Facturascripts
Facturascripts/Facturascripts