« Volver al listado

CVE-2026-27964

Estado: AplazadaBaja (3.9)—

FacturaScripts is an open source accounting and invoicing software. Versions 2025.7 and prior contain a Reflected Cross-Site Scripting (XSS) vulnerability through the fsNick cookie parameter. The application reflects the cookie's value directly into the HTML without sanitization. The fsNick cookie is rendered into the DOM without encoding. While the server does reject the modified session and forces a logout, the HTML containing the payload reaches the browser first. This lets the script execute immediately upon load, effectively beating the redirect. This issue has been fixed in version 2025.8.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-27964",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-27964",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "poc"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-05-19T13:00:46.326432Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security-advisories@github.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 3.9,
          "attackVector": "LOCAL",
          "baseSeverity": "LOW",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 2.5,
        "exploitabilityScore": 1.3
      }
    ]
  },
  "affected": [
    {
      "source": "security-advisories@github.com",
      "affectedData": [
        {
          "vendor": "NeoRazorX",
          "product": "facturascripts",
          "versions": [
            {
              "status": "affected",
              "version": "< 2025.8"
            }
          ]
        }
      ]
    }
  ],
  "published": "2026-05-18T22:16:38.703",
  "references": [
    {
      "url": "https://github.com/NeoRazorX/facturascripts/commit/9066e10326029adf012114e27eb5f3f33f78ecfd",
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/NeoRazorX/facturascripts/security/advisories/GHSA-gq5c-rw37-g46c",
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/NeoRazorX/facturascripts/security/advisories/GHSA-gq5c-rw37-g46c",
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0"
    }
  ],
  "vulnStatus": "Deferred",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security-advisories@github.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-79"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "FacturaScripts is an open source accounting and invoicing software. Versions 2025.7 and prior contain a Reflected Cross-Site Scripting (XSS) vulnerability through the fsNick cookie parameter. The application reflects the cookie's value directly into the HTML without sanitization. The fsNick cookie is rendered into the DOM without encoding. While the server does reject the modified session and forces a logout, the HTML containing the payload reaches the browser first. This lets the script execute immediately upon load, effectively beating the redirect. This issue has been fixed in version 2025.8."
    },
    {
      "lang": "es",
      "value": "FacturaScripts es un software de contabilidad y facturación de código abierto. Las versiones 2025.7 y anteriores contienen una vulnerabilidad de cross-site scripting (XSS) reflejado a través del parámetro de cookie fsNick. La aplicación refleja el valor de la cookie directamente en el HTML sin sanitización. La cookie fsNick se renderiza en el DOM sin codificación. Aunque el servidor rechaza la sesión modificada y fuerza un cierre de sesión, el HTML que contiene la carga útil llega primero al navegador. Esto permite que el script se ejecute inmediatamente al cargar, superando eficazmente la redirección. Este problema ha sido solucionado en la versión 2025.8."
    }
  ],
  "lastModified": "2026-07-24T13:10:00.223",
  "sourceIdentifier": "security-advisories@github.com"
}