<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:facturascripts:facturascripts:*:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3afacturascriptsfacturascripts/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Mon, 05 Oct 2026 18:48:11 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3afacturascriptsfacturascripts/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>PHP Object Injection in FacturaScripts via WidgetSelect</title><link>https://feed.craftedsignal.io/briefs/2026-10-facturascripts-php-injection/</link><pubDate>Mon, 05 Oct 2026 18:48:11 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-facturascripts-php-injection/</guid><description>Authenticated attackers can exploit a PHP object injection vulnerability in FacturaScripts versions prior to 2026.7 by injecting serialized objects into WidgetSelect multiple-select fields, leading to arbitrary file deletion.</description><content:encoded><![CDATA[<p>FacturaScripts versions prior to 2026.7 are susceptible to an insecure PHP object injection vulnerability located within the <code>WidgetSelect::processFormData()</code> method. The vulnerability arises because the application utilizes the <code>unserialize()</code> function on raw POST data submitted through multiple-select fields without implementing an <code>allowed_classes</code> filter.</p>
<p>An authenticated attacker can craft a malicious serialized <code>XLSXWriter</code> object and provide it as a field value during a POST request. Upon processing, the application deserializes the input, which triggers the <code>__destruct()</code> magic method of the <code>XLSXWriter</code> class. If leveraged correctly, this mechanism allows the attacker to delete arbitrary files on the web server, specifically targeting configuration files like <code>config.php</code> or sensitive backup data. This leads to a persistent denial of service or enables the attacker to hijack the application installation process by forcing a re-initialization of the system. This vulnerability highlights the significant risks associated with using <code>unserialize()</code> on untrusted input in PHP applications.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows for the deletion of critical application files, including <code>config.php</code>. This results in immediate denial of service (DoS) and potentially allows an attacker to hijack the FacturaScripts installation flow to gain unauthorized administrative access. The vulnerability requires authenticated access, limiting the scope to users with valid session credentials.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Update FacturaScripts to version 2026.7 or later to incorporate the patch for CVE-2026-104905.</li>
<li>Restrict administrative or privileged access to the application to prevent low-privileged users from reaching vulnerable input fields.</li>
<li>Review server-side file integrity and monitor for unexpected deletion events in the application's base directory.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>web-application</category><category>php</category><category>rce</category><category>file-deletion</category></item></channel></rss>