FacturaScripts to open-source'owe oprogramowanie do planowania zasobów przedsiębiorstwa i księgowości. Przed wersją 2025.8 istniała podatność reflected XSS w FacturaScripts. Problem dotyczy sposobu wyświetlania komunikatów błędów — używany jest filtr | raw Twiga, który pomija HTML escaping. Po wyzwoleniu błędu bazy danych (np. przekazując string zamiast integer) komunikat błędu zawiera dane wejściowe i jest renderowany bez sanityzacji. Podatność została naprawiona w wersji 2025.8.
▸ Pokaż oryginał (EN)
FacturaScripts is open-source enterprise resource planning and accounting software. Prior to 2025.8, there a reflected XSS bug in FacturaScripts. The problem is in how error messages get displayed. Twig's | raw filter is used, which skips HTML escaping. When triggering a database error (like passing a string where an integer is expected), the error message includes the input and gets rendered without sanitization. This vulnerability is fixed in 2025.8.
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:NFacturascripts
APPFacturascripts< 2025.8
Powiązane podatności
Przejęcie konta użytkownika w aplikacji Facturascripts (Account Takeover)
FacturaScripts is open-source enterprise resource planning and accounting software. Prior to version 2025.81, ...
FacturaScripts is open-source enterprise resource planning and accounting software. Prior to version 2025.81, ...
FacturaScripts is open-source enterprise resource planning and accounting software. In 2025.71 and earlier, a ...
Cross-site Scripting (XSS) - Stored in GitHub repository neorazorx/facturascripts prior to 2022.06.