FacturaScripts Stored Cross-Site Scripting Vulnerability in File Upload Functionality

Vulnerability

A stored cross-site scripting vulnerability has been identified in FacturaScripts prior to version 2025.7. This issue arises in the file upload feature, where authenticated users can upload specially crafted XML files containing executable JavaScript. The application later renders these files without adequate sanitization or enforcement of content types, enabling the execution of arbitrary JavaScript when the file is accessed. Since product files uploaded by regular users are visible to administrators, this vulnerability can be exploited to execute malicious JavaScript in an administrator's browser session.

Impact

Exploitation of this vulnerability allows for stored cross-site scripting, where uploaded files containing malicious JavaScript are executed in the context of the user accessing the file.

Remediation

Users can upgrade to FacturaScripts version 2025.7 to address this vulnerability.

Added: Dec 30, 2025, 8:19 PM
Updated: Dec 30, 2025, 8:19 PM

Vulnerability Rating

Custom Algorithm
spread
3.1
impact
5.4
exploitability
5.0
remediation
7.7
relevance
1.8
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.