PHP Object Injection in FacturaScripts via WidgetSelect
Authenticated attackers can exploit a PHP object injection vulnerability in FacturaScripts versions prior to 2026.7 by injecting serialized objects into WidgetSelect multiple-select fields, leading to arbitrary file deletion.
CVE search metadata
CVE search record: CVE-2026-104905. Severity: high. CVSS: 8.1. KEV: no. Product: FacturaScripts (< 2026.7). Brief: PHP Object Injection in FacturaScripts via WidgetSelect. Brief link: https://feed.craftedsignal.io/briefs/2026-10-facturascripts-php-injection/
FacturaScripts versions prior to 2026.7 are susceptible to an insecure PHP object injection vulnerability located within the WidgetSelect::processFormData() method. The vulnerability arises because the application utilizes the unserialize() function on raw POST data submitted through multiple-select fields without implementing an allowed_classes filter.
An authenticated attacker can craft a malicious serialized XLSXWriter object and provide it as a field value during a POST request. Upon processing, the application deserializes the input, which triggers the __destruct() magic method of the XLSXWriter class. If leveraged correctly, this mechanism allows the attacker to delete arbitrary files on the web server, specifically targeting configuration files like config.php or sensitive backup data. This leads to a persistent denial of service or enables the attacker to hijack the application installation process by forcing a re-initialization of the system. This vulnerability highlights the significant risks associated with using unserialize() on untrusted input in PHP applications.
Impact
Successful exploitation allows for the deletion of critical application files, including config.php. This results in immediate denial of service (DoS) and potentially allows an attacker to hijack the FacturaScripts installation flow to gain unauthorized administrative access. The vulnerability requires authenticated access, limiting the scope to users with valid session credentials.
Recommendation
- Update FacturaScripts to version 2026.7 or later to incorporate the patch for CVE-2026-104905.
- Restrict administrative or privileged access to the application to prevent low-privileged users from reaching vulnerable input fields.
- Review server-side file integrity and monitor for unexpected deletion events in the application's base directory.
Immediate actions
Upgrade FacturaScripts to 2026.7 or later
Mitigations
Upgrade FacturaScripts to version 2026.7
CVE-2026-104905