PT-2026-38616 · Neorazorx+1 · Facturascripts+1

Preritpathak

·

Published

2026-05-07

·

Updated

2026-05-27

·

CVE-2026-42878

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions FacturaScripts versions prior to v2026
Description An unauthenticated information disclosure issue in the Installer controller allows a remote attacker to trigger the phpinfo() function on a fresh deployment. By requesting the endpoint "/" with the parameter phpinfo set to "TRUE", an attacker can expose the full PHP configuration, server environment variables, filesystem paths, and loaded extensions. This exposure may include sensitive data such as database credentials, API keys, or application secrets stored as environment variables.
Recommendations Update to version v2026. As a temporary workaround, restrict access to the Installer controller or the "/" endpoint until the update is applied.

Exploit

Fix

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2026-42878
GHSA-VRXF-VRC4-22P7

Affected Products

Facturascripts
Facturascripts/Facturascripts