{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/facturascripts--2026.7/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:facturascripts:facturascripts:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.1,"id":"CVE-2026-104905"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["FacturaScripts (\u003c 2026.7)"],"_cs_severities":["high"],"_cs_tags":["web-application","php","rce","file-deletion"],"_cs_type":"advisory","_cs_vendors":["FacturaScripts"],"content_html":"\u003cp\u003eFacturaScripts versions prior to 2026.7 are susceptible to an insecure PHP object injection vulnerability located within the \u003ccode\u003eWidgetSelect::processFormData()\u003c/code\u003e method. The vulnerability arises because the application utilizes the \u003ccode\u003eunserialize()\u003c/code\u003e function on raw POST data submitted through multiple-select fields without implementing an \u003ccode\u003eallowed_classes\u003c/code\u003e filter.\u003c/p\u003e\n\u003cp\u003eAn authenticated attacker can craft a malicious serialized \u003ccode\u003eXLSXWriter\u003c/code\u003e object and provide it as a field value during a POST request. Upon processing, the application deserializes the input, which triggers the \u003ccode\u003e__destruct()\u003c/code\u003e magic method of the \u003ccode\u003eXLSXWriter\u003c/code\u003e class. If leveraged correctly, this mechanism allows the attacker to delete arbitrary files on the web server, specifically targeting configuration files like \u003ccode\u003econfig.php\u003c/code\u003e or sensitive backup data. This leads to a persistent denial of service or enables the attacker to hijack the application installation process by forcing a re-initialization of the system. This vulnerability highlights the significant risks associated with using \u003ccode\u003eunserialize()\u003c/code\u003e on untrusted input in PHP applications.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for the deletion of critical application files, including \u003ccode\u003econfig.php\u003c/code\u003e. This results in immediate denial of service (DoS) and potentially allows an attacker to hijack the FacturaScripts installation flow to gain unauthorized administrative access. The vulnerability requires authenticated access, limiting the scope to users with valid session credentials.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate FacturaScripts to version 2026.7 or later to incorporate the patch for CVE-2026-104905.\u003c/li\u003e\n\u003cli\u003eRestrict administrative or privileged access to the application to prevent low-privileged users from reaching vulnerable input fields.\u003c/li\u003e\n\u003cli\u003eReview server-side file integrity and monitor for unexpected deletion events in the application's base directory.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-05T18:48:11Z","date_published":"2026-10-05T18:48:11Z","id":"https://feed.craftedsignal.io/briefs/2026-10-facturascripts-php-injection/","summary":"Authenticated attackers can exploit a PHP object injection vulnerability in FacturaScripts versions prior to 2026.7 by injecting serialized objects into WidgetSelect multiple-select fields, leading to arbitrary file deletion.","title":"PHP Object Injection in FacturaScripts via WidgetSelect","url":"https://feed.craftedsignal.io/briefs/2026-10-facturascripts-php-injection/"}],"language":"en","title":"CraftedSignal Threat Feed - FacturaScripts (\u003c 2026.7)","version":"https://jsonfeed.org/version/1.1"}