PT-2026-5714 · Unknown · Facturascripts

Jaroslaw-Wawiorko

·

Published

2026-02-02

·

Updated

2026-02-23

·

CVE-2026-23997

CVSS v3.1

9.0

Critical

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions FacturaScripts versions 2025.71 and earlier
Description FacturaScripts software contains a Stored Cross-Site Scripting (XSS) flaw within the Observations field in the History view. The application fails to properly encode HTML entities when rendering historical data. This allows an attacker to inject and execute arbitrary JavaScript code in the browser of administrators viewing the history. The flaw can be exploited by logging in as a regular user, creating or editing a Delivery Note, inserting malicious JavaScript into the Observations field, and then having an administrator view the History tab for that note. Successful exploitation can lead to full account takeover, allowing an attacker to gain complete control of the system, including access to sensitive financial data and user configurations. The attack requires some knowledge of the application's internal API structure, which can be obtained through browser developer tools.
Recommendations Versions prior to 2025.71 should be updated.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2026-23997
GHSA-4V7V-7V7R-3R5H

Affected Products

Facturascripts