PT-2026-6305 · Unknown · Facturascripts
Lukasz-Rybak
·
Published
2026-02-03
·
Updated
2026-02-23
·
CVE-2026-25513
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
FacturaScripts versions prior to 2025.81
Description
FacturaScripts, an open-source enterprise resource planning and accounting software, contains a critical SQL injection issue in its REST API. Authenticated API users can execute arbitrary SQL queries through the
sort parameter. The issue resides in the getOrderBy() method of the ModelClass, where user-supplied sorting parameters are directly incorporated into the SQL ORDER BY clause without proper validation or sanitization. This impacts all API endpoints that support sorting functionality.Recommendations
Update to version 2025.81 or later.
Exploit
Fix
SQL injection
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Facturascripts